Aspex is fully offline. It never sends your data anywhere, requires no account, and has no telemetry of any kind.
What Aspex Does Not Do
Aspex never:- Sends tool schemas, server output, or scan results to any remote server
- Phones home or checks for updates after install
- Collects usage metrics, crash reports, or analytics
- Requires an account, login, or license key
- Reads credentials - only key names and file locations are reported, never values
- Transmits environment variables, config files, or filesystem paths off-device
- Persists any data outside your local machine
aspex-attack: The One Exception
aspex-attack (and the aspex scan redteam subcommand) actively calls live MCP tools with adversarial payloads. This is the only component that sends data over the network - and it sends data to your own MCP servers, not to Aspex or any third party.
Explicit opt-in consent is required before any probe is sent. Only probe servers you own or have authorization to test.
The Only Network Call
The sole network activity associated with Aspex is the binary download at install time:aspex scan, aspex trace, and aspex doctor.
Release Integrity
Every Aspex release ships with:- SHA-256 checksums for all binaries, verifiable before execution
- Full SPDX Software Bill of Materials (SBOM) listing every dependency and its license