Careful with your network. Careful with your data.
SubnetSleuth is made for networks you do not know yet, often someone else's. These are the rules it follows, and how you can check them.
It only reads
SNMP gets and walks only; no SNMP set is ever sent. Platform connectors make read-only API calls, and every request is checked against the connector's read-only list before it leaves your computer. Windows connectors run fixed, read-only scripts that are checked against an allow list. Configuration capture runs only "show" commands. Nothing on a device, platform or server is changed.
It stays inside your ranges
Every step that sends a packet (polling, following neighbours, sweeping, identifying hosts, port scans, deep scans, inspection) checks the scan's scope, its target ranges and your never-touch ranges first. A credential can be limited to the networks it belongs to, so it is never sent anywhere else, however wide a scan is.
Credentials stay on your computer, encrypted
Saved credentials are encrypted with Windows DPAPI, tied to your Windows account (the system keyring on Linux), or read from an environment variable you name. They are never written to a project file or an export, and they are masked in the log. Every use of a credential is recorded: which one, for what, against what.
Sign-ins go where they belong
A platform's credentials are sent only to the exact address you configured; they never follow a redirect to another host. Certificates are checked against the Windows certificate store, so a company's TLS inspection works without turning checks off.
What leaves your computer
Almost nothing, and never without you choosing it.
- To us: only when you choose Help ▸ Check for updates, the app asks subnetsleuth.com whether a newer version exists. That request carries no project data, no licence details and no identifiers beyond what any web request carries.
- To the systems you scan or connect: only the read-only requests described above.
- To an AI service: only if you set one up, only when you ask a question, and only the data shown by "Show what will be sent". Masking can replace addresses, MACs, serials and names with tokens first.
- Licence checks happen on your computer. A licence key is verified offline; there is no activation server and no phone-home.
What we never see
Your projects, your credentials, your scan results, your notes and your AI questions stay with you.
We do not run a cloud service for your data and there is no account to create. Payments are handled by PayPal; we receive your name, email and the organisation you give, to put on your licence, and never your card or bank details. See the privacy notice.
AI, on your terms
AI features are off until you configure them. With Claude Code, Claude Desktop or Cowork, questions go through Anthropic's own apps under your sign-in. With an API provider, they go only to that provider's address over HTTPS, and environment variables cannot redirect them. A thorough question lets the model list, read and search an export of the project, and nothing else: no commands, no file changes, no web browsing.
How it is built and checked
Tested before every release
About 1,300 automated tests, many against a simulated campus with real SNMP agents. Every connector is tested to send only reads and never to follow a redirect with a credential.
The built app is tested too
Every release is built on Windows, started in a self-test mode that opens every page and every export, and only then packaged.
Your authority, your call
Only scan networks you are responsible for or have written permission to inventory. SubnetSleuth's scope and exclusions help you stay within that permission; the licence agreement says so too.
Questions from your security or procurement team?
We are happy to answer a questionnaire or walk through how SubnetSleuth behaves.