Why Should You Trust Us?

Our tools attach to your code while it runs. They see your memory allocations, function calls, locks and coverage data. That’s a lot of trust to ask for, so this page explains plainly what we do with your data, what we don’t do, and how we protect what we hold.

The short version

  • Your code stays on your machines. Our tools run locally. There is no cloud service and no SaaS backend, and nothing about your application is uploaded anywhere.
  • No telemetry. Our tools don’t collect usage or diagnostic data. The only automatic outbound contact is a check for software updates, a version history check on the software updates dialog, and any telemetry required to support floating licences.
  • Works offline. Offline operation is fully supported.
  • Signed software. Every installer is code-signed, and the signing key is held on dedicated hardware.
  • No AI on your data. We never put anything you send us into an AI or machine-learning system without your explicit written consent.
  • We never see your card details. Payments are handled by Stripe, no credit card data is stored on our servers.
  • UK GDPR. We’re a UK company, and we handle personal data under UK GDPR and the Data Protection Act 2018.

Your code and data stay with you

Memory Validator, Performance Validator, Coverage Validator, Thread Validator and our other tools are native Windows applications that you install and run on your own computers. All the analysis happens on your computer. The data the tools collect, such as allocation histories, call trees, coverage results and lock analysis, is saved where you choose, and none of it is sent to us.

The tools don’t collect telemetry, usage statistics or analytics. The only automatic network contact is the update check, which tells you when a new version is available. Updates are never installed silently, and older installers stay available if you need to roll back.

If one of our tools crashes, it may offer to send us a crash report. Sending it is entirely up to you: nothing goes anywhere unless you choose to send it.

If we ever add telemetry in future, it will be opt-in and disclosed in advance. It would also be limited to non-personal data, such as which tool is used, the hardware specification and the operating system version.

Software you can verify

Every Software Verify installer is code-signed with a certificate issued by DigiCert. The private signing key is kept on dedicated hardware, and only the founder can approve a signed release. No contractor, partner or automated system has access to the signing key. Before you install, you can check the digital signature on any of our installers in Windows (right-click the file, then choose Properties → Digital Signatures).

What we hold about you

We keep the minimum we need to sell you a licence, deliver it and support you:

Data Why we hold it How it’s protected
Name, email address, company and postal address Your licence, invoices and support Kept on encrypted storage on our own premises
Licence name, products and expiry dates Licence delivery and update entitlement Kept in our web server database, hosted by Hostinger (ISO 27001 certified) and encrypted at rest
Order history and amounts paid Accounting, renewals and upgrade pricing Kept on encrypted storage on our own premises
Payment card details Never held by us Processed entirely by Stripe, a PCI-DSS Level 1 service provider

We don’t sell or rent your data, and we never pass it to third parties for marketing.

Floating licences

If you use floating licences, the licence service records the logged-on username, computer name and Windows machine identifier of whoever is currently holding a seat. This is used for one thing only: showing your colleagues who has a seat, so they can ask for it to be released. It isn’t kept after the licence session ends, and it isn’t shared with anyone outside your licence pool. This is disclosed in section 10 of our licence agreement.

When you send us code, dumps or logs

Sometimes the fastest way to fix a problem is for you to send us a reproduction case, a crash dump, a memory snapshot or a log file. When you do:

  • It’s confidential whether or not you have an NDA with us. Everything you send is treated as confidential by default.
  • We’ll sign your NDA. If you need one before sharing material, send it over. We have never refused to sign a customer’s NDA.
  • It stays inside Software Verify. We never share material from one customer with another customer. We never put it on the web, a file server or any external service.
  • It’s stored securely. Your material is kept on encrypted storage, or on physically isolated storage kept in a locked room.
  • No AI. Nothing you send us is used as input to any AI or machine-learning system unless you’ve given explicit written consent for that specific case.
  • Deleted on request. We keep support correspondence because it often helps when you contact us again later. If you’d like your material destroyed, tell us and we’ll delete it promptly.

Who has access

Software Verify is a small, founder-led company, and that limits who can reach your data. The founder holds the credentials for every critical system. Every critical account is protected by multi-factor authentication, including email, domain registration, source control, payments, hosting, banking and code signing. Each service has its own separate credentials, so a single compromised login can’t open everything.

We work with a very small number of trusted partners, one of whom has managed our web server for more than 20 years. Each partner’s access is limited to what their role needs. Access is reviewed when an engagement ends, and revoked if it’s no longer needed.

Privacy law and your rights

Software Verify Limited is registered in the UK, and our regulator for data protection is the Information Commissioner’s Office (ICO). We handle personal data under:

  • UK GDPR and the Data Protection Act 2018
  • EU GDPR, for customers in the European Union
  • CCPA/CPRA, for customers in California

You can ask us at any time to show you the personal data we hold about you, correct it, or delete it. If we ever had a personal data breach that put your rights at risk, we would notify the ICO within 72 hours, as the law requires, and we would contact the people affected without undue delay.

Privacy Policy

Cookie Policy

Security breaches

We’ve been in business since February 2002. We haven’t had a breach in 24 years.

There is no customer data on the webserver worth stealing, and that’s the only DNS identifiable machine on the internet.

Any binaries that could be tampered with will lose their Software Verify digital signature which mean web browsers will produce warnings if they are downloaded.

Who we sell to

Our tools exist to help developers find and fix bugs and improve software quality. If we know a buyer intends to use them for harm, such as exploitation, sabotage or black-hat attacks, we decline the sale and withdraw support, however much the deal is worth.

Questions procurement teams ask

Do your tools send our source code or binaries anywhere?

No. All analysis happens on your machines. The only automatic network contact is the check for software updates. Crash reports are sent only if you choose to send them.


Can we use your tools on an isolated or offline network?

Yes. Offline operation is fully supported. The tools don’t depend on any Software Verify server to run.


Is there a cloud component or SaaS dependency?

No. Our products are installed Windows software, sold on perpetual licences. You don’t need an online account to use them.


Do you use AI on our code or support data?

No, not without your explicit written consent for that specific case. Our products don’t include any AI features either.


How do we know an installer really came from you?

Every installer is signed with our DigiCert code-signing certificate. Before running an installer, check that its digital signature shows Software Verify.


Will you sign our NDA?

Yes. Send it over before you share anything sensitive.


Who processes our payment details?

Stripe. Your card details go straight to Stripe and never pass through our systems.


Will you complete our security questionnaire?

Yes. Email it to us and we’ll answer it directly.

Contact

For security, privacy or data protection questions, or to make a data request, email sales@softwareverify.com.

 

Fully functional, free for 30 days