What stays local

Local by default. Nothing leaves your machine unless you connect an external model.

  • Scan files, asset names, IP addresses and findings stay on your machine.
  • CASSI Security never receives your findings, in any mode.
  • The intelligence pack, a full vulnerability database, is downloaded to you. Every customer gets the same pack, so the download reveals nothing about your environment.
  • The daily sync sends your license key and nothing about your findings. Like any download, it exposes an IP address and a time.
  • Your imported data and reports live in a project folder you own.

Because the whole database is on your machine, answers come from the local copy rather than from a remote lookup. We never receive your findings. You decide whether any other service does.

What the pack sync sends

Every day CASSI downloads a full copy of the CVE Security vulnerability database to your machine. The sync sends your license key and nothing about your findings. Like any download, it exposes an IP address and a time. Every customer gets the same pack, so the download reveals nothing about your environment.

A full description of the sync request will be published here before launch.

How external models work

CASSI ships with IBM Granite, an openly licensed model that runs on your own hardware. That is the product, and it is what we recommend.

You can connect a different model if you accept the trade-off: OpenAI, Anthropic, another provider, or your own internal inference server. External models are off by default; you turn them on deliberately. You use your own API key, and requests go straight to the provider. Nothing passes through CASSI Security or InfoBakery LLC servers.

Data sent to a model you configure is your responsibility, and the Terms will say so. Read each provider's own data terms before you connect one:

What happens at license expiry

When a trial or subscription ends, CASSI shows a license-expired message and analysis stops. Your imported findings and past reports remain in your own project folder, and CASSI Security never received them.

Published before launch

We will add the following to this page once engineering has finalized each one:

  • Exactly what external-model mode sends to the model when you enable it.
  • Hardware requirements for the local model.
  • The complete list of data sources and their required credits.

Who operates CASSI

CASSI Security is operated by InfoBakery LLC, a Connecticut-based software company. InfoBakery LLC receives only the account and billing details needed to license the software. About CASSI Security.