Privacy policy.
Effective July 15, 2026. This covers ravensoftworks.com and the RavenSoftworks products (Defendrix AV and AxiomCAD). It is written in plain English on purpose; if anything here is unclear, contact us and a person will explain it.
- File scanning and design work happen on-device. Network features send only the data described below.
- This site runs no ad trackers and no third-party marketing scripts.
- We collect the minimum needed to run licensing and support, and we never sell any of it.
- Use the privacy request form for access, correction, or deletion, subject to the limited records described below.
What this website collects
Waitlist signups. If you join a waitlist, we store the email address you gave us and which plan you were interested in. We use it to tell you when the product launches and to send your founding-member discount. That is the whole use.
Sign-in. Accounts use a verified email address and password. RavenSoftworks stores only a memory-hard, uniquely salted password verifier protected by a separate server-side secret—never the password itself. Verification and recovery links are single-use and time-limited. When you sign in we set an opaque HTTP-only session cookie; it is not readable by page scripts.
Hosting and performance. The site is hosted on Vercel, which keeps standard server logs (IP address, requested page, timestamp) to run the service. We also use Vercel's cookieless analytics, which gives us aggregate page counts and load times. It sets no cookies and cannot follow you across other websites.
What the products collect
Defendrix contacts our license server to enforce your seat count. The server sees your license key, device and hardware identifiers, hostname, OS and app versions, connection identifier, and check-in timestamps. That is what powers activation and the dashboard device list.
Protection analysis and file contents remain on the device. When fleet synchronization is enabled, the configured Defendrix service receives bounded device health, engine state, settings fingerprints, scan and quarantine counts, and security-event summaries. A detection summary can include its event identifier, time, threat label, local path, file hash, verdict, action, and MITRE label. Login and audit summaries can include a username, source IP, result, and bounded note. This snapshot path does not send file contents, raw network packets, or keyboard input.
Eligible LAN peers can exchange bounded authenticated incident observations. The current consumer receiver validates and records those signals but does not accept a peer verdict or change local policy automatically. When remote support is explicitly enabled and approved, the rendezvous service handles encrypted session payloads plus routing metadata such as support IDs, timestamps, and packet sizes; the service cannot decrypt session content.
If you configure an alert webhook or approve remote file transfer, the selected alert or file is sent to the endpoint or administrator you chose. The security page covers these controls in more depth.
AxiomCAD follows the same policy: nothing leaves your machine unless you turn on an explicitly opt-in feature like cloud sync, and any telemetry a product has is documented in that product.
We send transactional email only: waitlist confirmations, account verification and password-recovery links, purchase records, and replies to your support requests. We do not send marketing blasts, and we will ask before we ever start. Our email is delivered through Resend, which processes the messages on our behalf.
Payments
When purchases open, checkout runs on Stripe or PayPal. Your card or account details go directly to them; we never see or store card numbers. We receive what we need to issue your license: the email you paid with, the plan, and a transaction reference.
Your data, your call
Send a privacy request through our first-party formand we will tell you what we hold about you, correct it, or delete it after completing appropriate identity checks. Deleting license records for an active subscription means the license stops working, so we will confirm before doing that. A confirmed permanent device-seat deletion retains a bounded deletion tombstone so the irreversible choice and replay protection survive reinstall; separate security audit, backup, billing, fraud-prevention, dispute, or legally required records follow their own retention rules. We answer within a few business days, usually faster.
Changes
If our data practices change, this page changes with the same release, and material changes get a note in the changelog. We will not quietly expand what we collect.