Skip to content

Privacy and Local Data Handling

Effective date: 2026-07-24

Vault Prospector is a local-first Windows application. The Preview does not operate a Vault Prospector cloud service and does not send project-controlled analytics or telemetry.

This document describes technical data handling for the current Windows Preview. It is not a promise that Windows, Microsoft Entra, Azure, GitHub, Chocolatey, or an organization's network and endpoint-security products collect no data; those services operate under their own policies.

Data processed

Vault Prospector processes the minimum data needed for the selected user workflow:

DataPurposeLocation and protectionDefault retention
Public-client application ID and identity account metadataReconnect the selected Microsoft Entra identity and show its access contextSQLCipher-encrypted local metadata databaseUntil the identity or all local data is removed
Microsoft Entra access and refresh tokensAuthenticate to Azure Resource Manager and Azure Key VaultApp-specific MSAL token cache protected by supported Windows mechanismsControlled by MSAL, Entra policy, sign-out, and identity removal
Tenant, subscription, vault, key, certificate, and secret metadataOffline discovery and searchSQLCipher-encrypted local metadata databaseUntil refreshed, removed, or all local data is deleted
CyberArk profile, safe, account, version, direct permission, and value-free audit metadataOperate the separately configured Privilege Cloud sourceSQLCipher-encrypted local metadata databaseSynchronized metadata is removed with its profile; local audit is retained until all local data is deleted
CyberArk Identity service-user client credentialAuthenticate an explicitly configured CyberArk profileSeparate per-profile DPAPI CurrentUser file with profile-specific entropyUntil rotated, locally revoked, the profile is removed, or all local data is deleted
CyberArk Identity and platform tokensAuthenticate one validate, sync, or retrieve operationProcess memory only; not cached by Vault ProspectorScoped to the operation
Secret value selected for reveal or copyPerform the explicit user actionProcess memory; optionally the Windows clipboardUI reveal is masked after ten seconds; clipboard clearing uses the configured interval if unchanged
Optional offline secret valueAllow an explicit offline workflowSeparate AES-GCM envelope with authenticated descriptor metadata and a DPAPI-protected key for the current Windows userDisabled by default; expires by policy, is invalidated after an incompatible security upgrade, or is purged by the user
Allow-listed diagnostic eventsTroubleshoot counts, status categories, and exception typesLocal newline-delimited JSON log with identifiers pseudonymizedUntil the user deletes local data; automatic log retention is not yet implemented
Local settingsRemember whether the product or an optional custom client ID is used, clipboard timeout, offline-cache preference, close behavior, and opt-in background metadata synchronizationLocal JSON settings file; it contains no client secret, token, or secret valueUntil the settings file or all local data is deleted
Recovery archivesPreserve a matched local-state set before reset/rotation and retain interrupted state for supportTimestamped directories under %LOCALAPPDATA%\VaultProspector-Recovery; protected values and keys retain their existing encryption/DPAPI boundariesRetained indefinitely by default; one selected app-generated archive can be permanently deleted only after exact typed confirmation and fresh Windows verification

Network activity

When the user signs in or synchronizes, Vault Prospector contacts Microsoft identity endpoints, Azure Resource Manager, and Azure Key Vault using the selected identity. Azure authorization is never expanded by the application. Metadata synchronization does not retrieve secret values.

A secret value is requested from Azure Key Vault only after the user explicitly chooses a reveal, copy, or cache operation and completes required local verification.

For an explicitly configured unreleased CyberArk profile, validate, sync, or retrieval contacts the configured CyberArk Identity and Privilege Cloud production endpoints. CyberArk metadata sync lists safes, direct member evidence, accounts, and versions but does not retrieve values. A CyberArk value is requested only after exact account/version selection, a non-sensitive reason, and fresh Windows verification. The reason is sent to CyberArk for its authoritative audit but is not stored in the local audit.

If the user explicitly enables notification-area background synchronization, the application may contact Microsoft identity endpoints, Azure Resource Manager, and Azure Key Vault metadata endpoints every 15 minutes while the main window is hidden and Windows reports network availability and external power. This path does not retrieve secret values, copy data, or create offline cached values.

Installing or updating through GitHub Releases, WinGet, or Chocolatey contacts those distribution services. Vault Prospector itself does not send those services vault content or application usage telemetry.

Clipboard and screen disclosure

Revealed values are visible to the signed-in Windows session. Clipboard values may be retained by Windows clipboard history, cross-device clipboard, remote-desktop software, endpoint tools, or another process before Vault Prospector clears them. Disable clipboard history and synchronization when organizational policy requires stronger isolation.

Vault Prospector cannot protect a deliberately revealed value from malware running as the same user or from a local administrator.

Telemetry and diagnostics

Project-controlled telemetry is disabled in the Preview. Diagnostic logs do not intentionally contain tokens, secret values, usernames, vault names, object names, private keys, certificate payloads, or decrypted cache content. Do not send diagnostic files publicly without reviewing them under organizational policy.

If telemetry is proposed later, it requires an updated public schema, explicit release review, and an updated notice before activation.

Voluntary Preview feedback

Preview feedback is collected only when an evaluator explicitly submits a public GitHub issue through the Preview feedback process. Vault Prospector does not create an issue, upload diagnostics, or associate application activity with a GitHub account.

A submitted issue and its attachments are public and are processed under GitHub's privacy terms. The feedback notice requires synthetic or non-production data and excludes credentials, tokens, identity and Azure-resource identifiers, resource/object names, secret values, and unreviewed diagnostics or screenshots. Choosing to submit after reading that public notice is the evaluator's explicit publication action. Suspected vulnerabilities use the private channel in SECURITY.md, not the feedback forms.

Removal and device migration

Removing an identity removes its MSAL account entry and local access mapping. Use application controls to purge item, vault, workspace, or all offline values.

Local revocation first persists a disabled/revoked state and then deletes the DPAPI-protected credential while retaining encrypted metadata. Removing a CyberArk profile also deletes its synchronized safe/account/version/permission metadata. Value-free local audit is retained for investigation. Neither local action revokes the service user in CyberArk Identity; an administrator must rotate or revoke it there when compromise is suspected.

Uninstall intentionally retains %LOCALAPPDATA%\VaultProspector to avoid silently deleting user state. To remove all Vault Prospector data, close the application, uninstall it, and delete that directory. DPAPI-protected keys are bound to the Windows user; copying the directory to another device or profile is not a supported backup or migration.

An existing encrypted database or offline-value envelope is opened only with its existing matched protected key. If that key is missing, Vault Prospector does not generate a replacement or alter the encrypted file. A same-account recovery copy is useful only when its data and keys directory are restored as one matched set. The Preview has no supported cross-device key migration or application-managed backup/restore workflow.

When a protected key or encrypted database fails validation, Vault Prospector preserves the state. Starting fresh requires the exact typed confirmation RESET and fresh Windows verification. The application then moves the entire local data directory to a timestamped sibling under %LOCALAPPDATA%\VaultProspector-Recovery and requires restart. The archive can contain encrypted metadata, protected keys, opt-in offline values, app-owned identity caches, settings, and redacted logs. It remains local and is not uploaded automatically. It is not a supported cross-device backup. The Settings page lists app-generated archives without opening their protected values. There is no automatic age or size deletion policy. Permanent deletion requires selecting one archive, typing DELETE ARCHIVE exactly, and completing fresh Windows verification; delete it only after deciding that recovery and support evidence are no longer needed.

Browser integration

The unreleased browser integration does not inspect or import saved browser passwords. A toolbar action sends only bounded page context needed for an exact fill decision: browser family, tab and frame identifiers, opaque document/gesture/field tokens, canonical top and frame HTTPS origins, field purpose, request identifier, and time. The extension does not persist a returned value.

Local browser mappings and value-free audit events are stored in the encrypted metadata database. The audit records include time, result, canonical origins, field purpose, and local identifiers but not the secret value. Vault Prospector does not send browser activity to project-controlled telemetry.

CyberArk integration

The unreleased CyberArk provider is separate from Azure identities, token caches, objects, browser mappings, and offline-value caching. SQLCipher does not store the client credential, Identity access token, platform token, retrieval reason, or account value. The protected credential file is bound to the current Windows account and profile identifier.

Local CyberArk audit records operation, result, profile/account identifier, safe, version, time, and a fixed safe message. They do not store the credential, tokens, business reason, or account value. CyberArk remains authoritative for server-side access and audit records.

Machine-managed enterprise policy

The unreleased Windows application can read policy that an administrator places under HKLM. Allowed-tenant entries are Microsoft Entra tenant GUIDs; provider/identity choices and clipboard/offline-cache limits are also configuration data. Vault Prospector does not create, change, delete, upload, or copy these values into diagnostic events. The Settings summary reports only counts and bounded state, not configured tenant identifiers. See Machine-managed enterprise policy.

Mobile applications

The unreleased Android and iOS applications store encrypted metadata and app-owned identity state inside platform-private storage. Value caching is disabled by default. Protected key material is device-bound and local data is excluded from operating-system backup and transfer paths. Losing that key material requires local reset, reauthentication, and metadata resynchronization.

Mobile authentication and vault requests go directly to Microsoft and Azure. The project does not operate a mobile relay, collect product analytics, track users, sell data, or serve advertising. iOS pasteboard writes are local-only and expire; Android marks copied content sensitive. Both platforms clear only unchanged app-owned content on timeout or background. Other software may read content before it is cleared. Android blocks ordinary screenshots with a secure window. iOS covers background snapshots and reacts to active capture but cannot prevent a screenshot already taken.

The iOS privacy manifest and Android data-safety baseline declare no project-controlled collection or tracking. Final store declarations must be reconciled against the exact signed artifact, transitive SDK disclosures, and observed live traffic before submission.

Security and privacy contact

Report suspected vulnerabilities privately as described in SECURITY.md. For a technical privacy question, contact kris@hybridsolutions.cloud. Do not email credentials, tokens, private keys, or secret values.

Preview software. Direct packages are unsigned and display Unknown Publisher — verify the published SHA-256 before installing.