Frequently asked questions

Quick answers about installation, protection modes, privacy, and beta expectations.

More detail: Getting started · Features · Documentation

?
Is CustosXI free? Freeware, no paywall, optional donations.

Yes. CustosXI is free to download and use (freeware). There is no premium tier. Donations are optional via the Support page.

?
Is CustosXI an antivirus? Network monitor - not a replacement for AV.

No. CustosXI focuses on network visibility, DNS control, scoring, and local enforcement. It does not replace Windows Defender, commercial antivirus, or enterprise EDR/SIEM products.

?
Do I need Npcap? Not for Light mode; yes for Full capture.

Not immediately. Without Npcap, CustosXI runs in Light protection: DNS sinkhole, firewall, scoring, Top Risk, and timeline still work.

Install Npcap when you want live packet capture, Live Traffic, GEO, AI/Anomaly tuning, and Suricata-related packet features. Then switch to Full protection in Settings → General.

Comparison table: Light vs Full.

?
What is Light vs Full protection? Two experience modes in one app.

Light - DNS + firewall + signals without raw capture. Good first day setup.

Full (Enterprise Capture) - everything in Light plus live traffic, packet signals, and capture-dependent settings.

CustosXI picks Light automatically if Npcap is missing, even if you wanted Full. Install Npcap and switch modes when ready.

?
Does CustosXI send my traffic to the cloud? Local-first by design.

Everyday analysis runs on your PC. CustosXI does not upload captured packets or local logs to project servers by default.

Network calls happen only for features you enable (update checks, optional reputation APIs, feed downloads, etc.). See Privacy Policy and Security.

?
Why does Windows SmartScreen warn me? Unsigned public beta builds.

Beta installers may not be code-signed yet. SmartScreen can flag unknown publishers. Download only from custosxi.com or downloads.custosxi.com and verify SHA-256 when published. Guide: Verify your download.

?
How do I update CustosXI? In-app check and About page download.

Enable update checks in Settings → General. When a newer build exists, the title bar shows a suffix and Settings → About offers Download installer (opens the official latest URL).

Changelog: Release notes.

?
DNS or firewall broke my network - what now? Emergency recovery first.

Follow Emergency recovery: restore default DNS, emergency firewall unblock, or Helper CLI commands before reinstalling.

?
What gets removed on uninstall? You choose whether to delete local data.

The uninstaller removes the application and service. You can opt to delete local data under ProgramData, per-user AppData, and related registry keys. Firewall rules created by CustosXI should be cleaned up via uninstall maintenance or emergency recovery if needed.

?
Where is data stored? Local SQLite by default.

Default database: SQLite under ProgramData\CustosXI. Logs are JSONL files on disk. Optional PostgreSQL is supported for larger setups. See Database guide.

?
How do I report a bug or request a feature? Contact page with version info.

Use Contact and include your product version from Settings → About, Windows version, and steps to reproduce. Security issues: security@custosxi.com.