Windows Network Security & Privacy
How CustosXI approaches Windows network security, local data processing, safe downloads, external components, and responsible vulnerability disclosure.
Local-first Windows network security
CustosXI analyzes network traffic, DNS activity, connections, firewall events, and security signals on your Windows PC. It is designed as a local-first Windows network security and monitoring tool, not as a cloud SIEM. See Privacy Policy for details about what leaves your machine.
CustosXI does not automatically send captured network traffic, raw packets, or local analysis logs to project servers, except for features you explicitly enable (documented third-party APIs, update checks, etc.).
Security monitoring and threat detection
CustosXI combines multiple local signals to help investigate potentially suspicious network activity. Depending on the enabled features and configuration, these can include network traffic, DNS activity, Windows Firewall events, IP and ASN information, reputation data, anomaly detection, and optional Suricata alerts.
These signals are intended to support investigation and network visibility. They should not be interpreted as a guarantee that every malicious activity will be detected or prevented.
What CustosXI is not
- Not an antivirus or anti-malware product.
- Not a replacement for Windows Firewall or enterprise EDR/SIEM.
- Not a guarantee of complete threat detection or prevention.
Official downloads and verification
Install CustosXI only from custosxi.com, downloads.custosxi.com, or mirrors explicitly listed by the project. When available, verify the published SHA-256 checksum on the Download page. Avoid installers obtained from unofficial mirrors, forums, or file-hosting sites.
Privileges & external components
- Administrator rights may be required for install and the background service.
- Npcap is not bundled - install only from official Npcap sources at npcap.com when live capture is needed.
- Suricata is not bundled - optional GPL v2 third-party software; you install, update rules, and operate it separately.
- PostgreSQL server, GeoLite2 databases, and threat-intel feeds are not shipped with CustosXI; optional client libraries or app features may contact services you configure.
- Optional add-ons may call external APIs with keys you provide - review each vendor's security posture and terms.
Responsible disclosure
If you believe you found a security vulnerability in CustosXI or the official website, please report it responsibly before public disclosure.
- Email: security@custosxi.com
- Include: affected version, Windows version, clear reproduction steps, impact assessment.
- Do not include unnecessary personal data, full packet captures, or secrets.
- Allow reasonable time for investigation and remediation before publishing details.
Website security and privacy
HTTPS is enforced via Cloudflare. The website avoids embedded third-party trackers and does not use on-site contact forms that store submitted messages. Security reports and other contact requests are handled through email links instead.
Custos