Privacy
The short version: the CLI sends nothing to WhosePort. The dashboard receives only what the local agent sends after redaction.
Local use
The CLI and the local agent run entirely on your machine. Without a cloud account, no data is transmitted to WhosePort. Investigations that call a model use the provider you configured, under that provider's terms.
With the dashboard connected
The local agent uploads normalized runtime evidence. That means:
- Listening ports, process names, commands and working directories.
- Project names, frameworks, Git branch names.
- Container names, images, published ports and networks.
- HTTP status codes and timings for local services.
- Recent log lines, with secrets redacted before upload.
- The variable names in project .env files and the host and port each URL points at. Never the values.
It does not upload source code, arbitrary files, or unredacted secrets. Evidence is redacted again when it reaches the cloud.
Account data
- Email address and name, for sign-in.
- Organization membership and roles.
- Approvals you grant or reject, with timestamp and note, on the investigation timeline.
Retention and deletion
Each environment keeps its most recent 200 snapshots; older ones are deleted automatically. Investigation history is kept while your organization exists. Self-service deletion is not available yet: email privacy@whoseport.com to have your account and data deleted.
Subprocessors
Cloud hosting, and the model provider that runs cloud investigations (Anthropic, OpenAI or Google Gemini). There is no payment processor during early access.