Security
A deliberately small launch surface
The launch website has no Chowder customer login, password, MFA or billing portal. Paddle handles checkout while Clarity Soft owns activation codes and signed entitlements; scans and scan history remain local.
No Chowder customer identity
Account, organisation and administration code is dormant and excluded from launch routing. Any later reactivation requires a separate security and architecture review.
Local scan data
Desktop scans, file names, detection results, history and quarantine stay on the customer's device. The marketing platform does not receive malware samples or local scan history.
Separated commerce and licence authority
Paddle handles checkout, tax and receipts. Clarity Soft independently issues opaque activation codes and bounded signed entitlement leases. A browser return page never grants Pro, and no merchant API token is shipped to a client.
Safe fallback
Licence expiry, cancellation or a bounded offline failure falls back to Standard. It does not disable basic scanning or delete local history and quarantine.
Clearly labelled downloads
Download pages identify the platform, architecture and test status, and withhold unavailable packages. When a direct artifact is listed, its version and SHA-256 checksum will appear with it. Planned platforms are not presented as available.
Website transport
Production traffic is designed to enter through Cloudflare Tunnel and ModSecurity/OWASP CRS, with HTTPS, HSTS, strict content-security and framing policies. The site will describe these controls as live only after deployment.
Honest scope
Chowder is a graphical malware scanner powered by ClamAV. It is not an EDR product. Launch availability is limited to Linux x64 and Synology DSM x86_64 after their native gates pass; Windows is not marketed or sold at launch.