Privacy

octomon measures your connection, on your machine, for you. Nothing about you is recorded by us, and this page is the proof: the only dashboard we have is published below, for everyone to see.

The promise

Everything octomon learns stays on your machine. Baselines, incident history, speed tests, recordings: all local files you can read, export, or erase (Ctrl+R removes everything). No telemetry, no accounts, no identifiers.

As a network tool, octomon does make outbound requests, to ping gateways and other IPs, DNS resolvers, time servers and speed-test backends. Every endpoint it contacts, when, why, and exactly what is sent is listed in the README's network table. Each request identifies itself as octomon/<version> (network monitoring tool; +https://octomon.dev).

A word on where this ethic comes from: octomon's author works at Cloudflare, a company with a long-standing commitment to privacy. octomon is a personal project, not a Cloudflare product, but it inherits that same moral compass: collect nothing you don't need, and be able to prove it.

The one endpoint we operate: /edge

octomon calls https://octomon.dev/edge at startup, on a network change, and every 15 minutes. Its only purpose is to improve the quality of the monitoring: the Cloudflare edge answers with facts about your connection that your machine cannot see from the inside: which PoP is serving you, which ISP network your traffic arrives from, the edge's own TCP round-trip measurement of you (a latency reading that works even on networks that block ping), and the latest released octomon version, so the client can mention when an update exists.

That answer goes to you and is stored nowhere. We keep no detailed logs. The only thing we store is a count: one request happened, from octomon version x.y.z, because of a start, a network change, or the 15-minute refresh: the version and one of those three constant labels, and nothing else. Every octomon instance sends the identical labels, so they link nothing to anyone; the version describes the software, not you. Together they let the graph below estimate what versions of octomon are running. No IP address, no location, no identifier of any kind is retained, which also means we cannot count unique users, only requests, a deliberate limitation.

Don't want even that? Set edge_check_url = "" in octomon's config and it is never called. The row simply disappears from the Network panel.

the fine print, honestly

octomon.dev is served by Cloudflare, so Cloudflare's platform handles the HTTP requests the way it does for every site behind it; that is true of any request to this domain, not just /edge. The website (not the tool) uses Cloudflare Web Analytics, which is cookieless. Our own code on /edge stores the version-family count described above, and nothing more.

Our whole dashboard, published

This graph is everything we can see: /edge requests per day, by octomon version, for the last 30 days. Day buckets keep it coarse in time, and the version (like 0.8.1) names a public software build, not a person. The line over the bars is how much octomon ran: every running copy refreshes /edge on a 15-minute tick, so each refresh call stands for a quarter of an hour of runtime, and refresh calls ÷ 4 ≈ the hours of octomon running that day. An estimate by design, and one you can recompute from the same public data, octomon.dev/edge/stats. There is no other dashboard, private or otherwise.

/edge requests · last 30 days

loading the live numbers…

Code signing

Windows binaries of octomon are signed. Free code signing provided by SignPath.io, certificate by SignPath Foundation. Every release is built by GitHub Actions from the public repository, and the signing request is made from inside that build, so what is signed is what the published source produces. Each release's signature is approved by hand before it is issued.

The people involved, by role:

  • Author, who writes the code: Simon Thorpe (securitypedant).
  • Reviewer, who reviews changes before they are merged: Simon Thorpe.
  • Approver, who approves each release for signing: Simon Thorpe.

On data, the statement SignPath asks every signed project to make, and which this whole page exists to back up: This program will not transfer any information to other networked systems unless specifically requested by the user or the person installing or operating it. Running a network monitor is that request: the pings, DNS queries and connectivity checks it sends are the measurements you started it to take, every one is listed in the README's network table, and the only endpoint we operate is described above. Nothing about you is sent anywhere, and nothing is sent at all unless octomon is running.

To check a download yourself: every release on GitHub publishes a .sha256 beside each archive, the Windows installer verifies the archive it downloads against that checksum before unpacking it, and winget verifies the same hash from its manifest. A signed octomon.exe shows SignPath Foundation as the publisher in its file properties.

Your own data, on your own disk

The files octomon keeps locally (CSV recordings, learned baselines, incident history) include your SSIDs, gateway and addresses. Treat them as you would any file describing your network, especially the Shift+D support bundle, which is designed to be shared with whoever is helping you debug.

Questions, or something on this page that isn't clear enough? Open an issue: github.com/securitypedant/octomon.