FAQ

Short answers to honest questions.

If something is missing, write to founders@heimwall.ai. A person answers.

Product

What it does and where it runs.

The tools we cover, the one platform we ship, and what happens when we are not there.

Which tools does HeimWall cover?

Cursor, Claude Code, Copilot, ChatGPT Desktop and Windsurf. We instrument the local app. No browser extension, no proxy. The detection engine is shared across all of them, so adding the next tool is a release rather than a rewrite.

Does it work on Windows or Linux?

macOS 13+ on Apple Silicon. That is where agentic coding lives today, so that is where all of the engineering goes. Windows is on the roadmap. Linux is not. One platform done completely beats three done halfway.

What is the detection latency?

The engine is built against a hard 50-millisecond budget, and a benchmark fails the build if the mean scan crosses it. What we will not give you is a p95 across real machines, because we do not collect timings from anyone’s laptop and we are not going to start. The rules run on the machine, outside the send path. Your prompt never waits on a scan, and nothing we do can slow the tool down.

What happens if the agent crashes?

Nothing happens to your work, and that is by design. HeimWall is read-only: it observes the composer, it never carries your traffic, so there is no gate to fail and nothing for a dead process to hold up. If the agent stops, detection stops and your tools run exactly as they did before we were installed. Detect and warn in real time is the whole contract.

Do I need admin rights to install?

For a fleet, MDM is the path we build for. Jamf, Kandji or Intune, signed and notarized, zero touch. For a single install it is a 4.1 MB notarized DMG. The engineer approves the macOS Accessibility prompt on first launch and nothing deeper is required.

How does an engineer know they are being recorded?

The agent asks on first launch and names what is detected and what leaves the device. After that the engineer can open the same page a manager sees about them, and can pause capture from the app. Every dashboard page carries the line that this data cannot be used in performance review, and that line comes straight out of the contract.

Privacy

What we see and what we never hold.

The part engineers are right to ask about first.

Does HeimWall read my prompts?

Yes, on your machine and only there. Detection runs locally, and matched values are masked before anything is written to our records. The free app sends no prompt data at all. On a Team plan what leaves is redacted metadata: a category label, a severity, a count, per-match hashes, and a masked snippet capped at 500 characters. Words you typed around a secret can survive in that snippet. The secret itself does not.

How does the capture actually work?

The agent runs locally next to the tool. It reads the composer through the macOS Accessibility API and watches the clipboard, runs 47 deterministic rules over what it finds in memory, and masks every match before a record exists. Detection makes no network call and uses no model. Capture is read-only: HeimWall never sits between you and the AI tool, never touches what you send, and adds zero latency. Accessibility is a serious permission, which is exactly why the capture path does nothing but read.

What does my manager actually see?

A row. Category, severity, which tool, which engineer, and how many values were masked. Not the text, not the file, not the secret. Outside Investigation Mode, the dashboard has no view that renders the content, which is a different thing from a view that hides it.

Is this used for performance review?

No. By contract. The terms bar safety scores, flag history and any HeimWall-derived signal from performance review, promotion and compensation decisions. The dashboard restates that on every page and you cannot dismiss the banner. Using it that way is a breach.

When can anyone see a raw prompt?

Through Investigation Mode, and through nothing else. Opening one takes a second factor, a chosen reason and 50 characters of written justification. The engineer is notified. It expires in 24 hours. The whole sequence appends to a per-org hash chain on a table that rejects updates and deletes, so nobody can quietly tidy it up afterward. It exists for incidents, not for browsing.

Security and compliance

What we hold, with no rounding up.

If we had the certificate we would show you the certificate.

Do you have SOC 2, HIPAA or GDPR?

No certifications yet, and we will not imply one. What we do have is an architecture that keeps the riskiest data out of our hands: secrets are masked on the device before anything reaches us. That is the core of our GDPR posture, enforced in code rather than in a binder. The day a SOC 2 Type II report exists, it will be linked right here. HIPAA eligibility arrives with BYOK and on-prem on the Enterprise track.

Can I self-host or run this on-prem?

On-prem is on the Enterprise roadmap for v1.5, month 12 and later. If you are in a regulated industry we would rather hear from you while it is still being designed than after. Write to founders@heimwall.ai.

Where is the metadata stored?

us-east-1 today, on Supabase. An EU region is on the v1.5 roadmap. Enterprise on-prem skips the question entirely.

What can you decrypt?

Not the sealed content. The manager’s keypair is generated in their own browser and what we store is a passphrase-wrapped blob we cannot open. If the manager forgets the passphrase, we cannot recover it for them, and that is the trade the design makes on purpose.

Pricing and billing

Contracts, upgrades, refunds.

The tiers themselves live on the pricing page. This is everything around them.

Can I upgrade or downgrade mid-year?

Yes. Upgrades prorate immediately, so you pay the tier difference for the rest of the term. Downgrades take effect at the next renewal. Annual commits take 10 percent off at two years and 20 percent at three. Tiers and what is in them are on the pricing page.

Is there a free trial for Team or Business?

Solo is free forever and covers one developer, so the cheapest way to evaluate the detection engine is to run it on your own machine first. For Team and Business we run 30-day paid pilots on a $15K deposit that converts to your first invoice if you sign. That keeps the pilot short and keeps both sides serious.

What is the refund policy?

Annual plans refund in full for any reason inside the first 30 days and are non-refundable after that. Enterprise terms are negotiated case by case.

The cheapest answer is to run it.

The free Mac app is the same detection engine as the paid product, with no account and no manager attached. It sends no prompt data.