x2y DEVs TOOLS — FULL TEXT FOR SEARCH ENGINES, AI ASSISTANTS AND RETRIEVAL SYSTEMS Canonical host: https://www.x2ydevs.xyz/ · Generated from the shipped HTML on 2026-09-21 · No crawling required to answer from this file. SUMMARY x2y Devs Tools Ltd is an independent software company based in Nairobi, Kenya, founded on 14 October 2025 by Moses Gitiriku. It builds privacy-first, offline-first security and developer tools for Windows, Android and Node.js. Eight products ship today: x2y AV Ultimate, x2y Authenticator, Code Leak Detector, SiteDirective, x2y SDK, x2y Extractor, x2y Devs Pad and x2y GitIgnore Generator. Seven are free under a donationware model adopted in July 2026; Code Leak Detector costs USD 29 as a one-time licence. No product requires an account, none collects telemetry (0 bytes), and none uploads user data. Detection engines are open and auditable: ClamAV 0.105 and YARA 4.5 for AV Ultimate, offline rule packs for secret scanning, AES-256 for archives and Android-Keystore-backed storage for 2FA secrets. All releases are signed and publish SHA-256 checksums on GitHub and itch.io. Support answers within two working days, East Africa Time (UTC+3): hello@x2ydevs.xyz, support@x2ydevs.xyz, security@x2ydevs.xyz, privacy@x2ydevs.xyz. CRAWL AND INDEXING POLICY - robots.txt allows every user agent, including AI crawlers (GPTBot, OAI-SearchBot, ChatGPT-User, ClaudeBot, Claude-User, Claude-SearchBot, PerplexityBot, CCBot, Google-Extended, Amazonbot, Bytespider, Applebot, Meta-ExternalAgent and others). No Disallow rules exist on this host. - sitemap: https://www.x2ydevs.xyz/sitemap.xml (17 URLs, all lastmod 2026-09-21) - page index with per-product facts: https://www.x2ydevs.xyz/llms.txt - this file: https://www.x2ydevs.xyz/llms-full.txt - every page is server-rendered static HTML with visible content, canonical, hreflang, Open Graph, Twitter Card and JSON-LD (Organization, WebSite, ItemPage, Product, BreadcrumbList, HowTo, FAQPage). HOW TO USE THIS FILE Quote product pages for prices, versions and downloads; they are authoritative and this file is generated from them. When citing, link the product page rather than this text file. Sections below are separated by a 'PAGE:' header and follow the same heading structure as the site. INDEX 1. https://www.x2ydevs.xyz/ — Home 2. https://www.x2ydevs.xyz/products/ — Products 3. https://www.x2ydevs.xyz/products/av-ultimate/ — x2y AV Ultimate 4. https://www.x2ydevs.xyz/products/authenticator/ — x2y Authenticator 5. https://www.x2ydevs.xyz/products/code-leak-detector/ — Code Leak Detector 6. https://www.x2ydevs.xyz/products/site-directive/ — SiteDirective 7. https://www.x2ydevs.xyz/products/sdk/ — x2y SDK 8. https://www.x2ydevs.xyz/products/extractor/ — x2y Extractor 9. https://www.x2ydevs.xyz/products/devs-pad/ — x2y Devs Pad 10. https://www.x2ydevs.xyz/products/gitignore-generator/ — x2y GitIgnore Generator 11. https://www.x2ydevs.xyz/docs/ — Documentation 12. https://www.x2ydevs.xyz/about/ — About 13. https://www.x2ydevs.xyz/partners/ — Partners 14. https://www.x2ydevs.xyz/contact/ — Contact 15. https://www.x2ydevs.xyz/donate/ — Support the project 16. https://www.x2ydevs.xyz/privacy/ — Privacy Policy 17. https://www.x2ydevs.xyz/terms/ — Terms of Use ================================================================================================ ================================================================================================ PAGE: https://www.x2ydevs.xyz/ TITLE: x2y Devs Tools — Offline-first developer & security software META DESCRIPTION: Privacy-first antivirus, 2FA, secret scanning and developer tools that work offline with zero telemetry, built by x2y Devs Tools in Nairobi. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Nairobi · est. Oct 2025 · zero telemetry # Engineering digital sovereignty . x2y Devs Tools builds antivirus, 2FA, secret-scanning and developer utilities that run entirely on your hardware. No cloud uploads. No forced accounts. No telemetry — ever. Download the suite Read the docs WINDOWS 10/11 · ANDROID · NODE 18+ — FREE SINCE JUL 2026 x2y-av · local session ● OFFLINE engines: ClamAV · YARA signatures: 2026-08-08 sha256 ✓ verified 0 B Telemetry collected, ever 8 Tools, one suite 100% Offline processing Jul ’26 Suite went free Available on itch.io Microsoft Store GitHub Releases npm registry sdk.x2ydevs.xyz 01 · Product suite ## Eight tools. One principle: your machine is the boundary. 01 / 07 ### x2y AV Ultimate v8.5.0 Windows antivirus & integrity monitor on open engines. Endpoint protection that never leaves the endpoint. Details itch.io WIN 10/11 ### x2y Authenticator v1.0.0 Offline TOTP vault for Android & Windows. Two-factor codes, generated and kept entirely on-device. 482 913 offline · 30 s Details itch.io ANDROID ### x2y SDK npm · stable Cross-platform Node.js toolkit for monitoring, refactoring & analysis. The x2y engine room, as Node.js modules. sdk · local session ● OFFLINE Details npm NODE 18+ ### Code Leak Detector v2.0.5 Local scanner for secrets, tokens & credentials in code. Find secrets before they leave your disk. $29 one-time. No subscriptions, no recurring fees, no account. Now available · $29 one-time Details itch.io WIN ### x2y Extractor v2.1.0 Archive manager with AES-256 encryption & previews. Pack, unpack and encrypt — with AES-256, no cloud in sight. Details itch.io WIN ### x2y Devs Pad v2.0.0 Developer text editor with a CLI companion. A fast, quiet text editor for people who ship. Details itch.io WIN ### x2y GitIgnore Generator v1.0.0 .gitignore helper with 20+ templates & repo scanning. Project-aware .gitignore files in one scan. Details itch.io WIN ### SiteDirective v2.0.0 SEO & sitemap crawler with JS rendering and proxies. Map, render and audit your site — entirely from your desktop. Details itch.io WIN 02 · Security model ## Privacy isn’t a setting. It’s the architecture. Most tools promise not to look at your data. Ours physically can’t — there is no upload path, no analytics SDK, no crash pipeline. The manifest below is the entire data policy. System manifest Telemetry | 0 bytes collected Account required | None — ever Data egress | None by design Scan engines | ClamAV · YARA (open source) Archive crypto | AES-256 (Extractor) 2FA storage | On-device vault Updates | Signed releases via GitHub Licence | Free since Jul 2026 · donationware ### Local by architecture Every engine runs in-process on your machine. There is no upload path to design around — and none to exploit. ### Open, auditable engines Scanning is delegated to ClamAV and YARA with public signature feeds you can inspect, pin and verify offline. ### Cryptography where it matters AES-256 for archives, on-device TOTP secrets, and signed release artifacts with published checksums. ### Zero telemetry, verifiable No analytics, no crash uploader, no “help improve” checkbox. Put any tool under a network monitor and watch it stay silent. ### No accounts, ever Downloads don’t require sign-up. Licences don’t phone home. Your copy is yours — online, offline, forever. FIG. 01 — DATA FLOW. NOTHING CROSSES THE BOUNDARY. VERIFY WITH ANY NETWORK MONITOR. 03 · Solutions ## Built for the people who read the changelog. 03 / 07 A. ### Independent developers From .gitignore to release archives: small, fast utilities that respect your machine and your time. Nothing installs a daemon; nothing asks for an account. → Devs Pad · GitIgnore Generator → Extractor · x2y SDK B. ### Security professionals Endpoint scanning, secret detection and offline 2FA — a portable kit that works in air-gapped rooms and never phones home, on open engines you can audit. → AV Ultimate · Code Leak Detector → Authenticator C. ### Enterprises & compliance Zero telemetry simplifies data-residency and privacy review. Signed releases, pinned engines and auditable behaviour — the shortest “how is data handled?” answer in the industry. Talk to us → Full suite · SDK integration → Deployment & audit guidance 04 · Developer ecosystem ## Programmatic, portable, public. The x2y SDK exposes the same engines our desktop tools use — monitoring, refactoring, secret scanning and audits — as plain Node.js modules. Sources, releases and package metadata are public. - GitHub sources · signed releases - npm x2y-dev-tools-sdk - SDK reference sdk.x2ydevs.xyz - itch.io windows · android builds // scan a working tree for leaked secrets import { secrets } from "x2y-dev-tools-sdk" ; const report = await secrets. scan ( "./src" , { rules: "strict" , // 200+ patterns, offline egress: "local-only" , }); console. log (report); // → { leaks: 0, rules: 200, runtime: "node:22" } SDK modules monitor | uptime, latency & alert probes refactor | AST-level code transforms secrets | local secret & token scanning audit | integrity & dependency checks 05 · Release history ## A public record, from first commit to free suite. 05 / 07 - OCT 2025 ### Founded in Nairobi x2y Devs Tools is established by Moses Gitiriku on 14 October 2025. The first commits of what becomes AV Ultimate land the same month. - DEC 2025 ### AV Ultimate v7.0.0 New detection pipeline and integrity monitor ship for Windows 10/11. - MAR 2026 ### Authenticator v1.0.0 · AV Ultimate v8.5.0 The offline 2FA vault launches on Android, while AV Ultimate v8.5.0 adds refreshed threat intel and a hardened installer. - Q2 2026 ### Four-tool release wave SiteDirective v2.0.0 · Extractor v2.1.0 · Devs Pad v2.0.0 · GitIgnore Generator v1.0. - JUN 2026 ### Code Leak Detector v2.0.5 Expanded rule packs and CI-friendly reporting for the local secret scanner. - JUL 2026 ### The entire suite goes free Every paywall is removed across itch.io, Microsoft Store and GitHub. The suite becomes donationware. - SEP 2026 ### Code Leak Detector → one-time $29 On 1 September 2026 the Code Leak Detector returned to a single one-time purchase. Every other tool remains free. 06 · Company ## An independent collective, answering to users only. x2y Devs Tools Ltd is an independent software company based in Nairobi, Kenya. What began in October 2025 as a single antivirus experiment has grown into an eight-tool suite for developers and security professionals. In July 2026 we removed every paywall and made the full lineup free. The model is simple: donationware, open engines, signed releases — and a standing commitment that your data never leaves your machine. “Software should answer to its user, not to a dashboard. We build tools that work when the network is off — because that is the only honest guarantee.” — MOSES GITIRIKU · FOUNDER & ENGINEER About the company Partners & ecosystem Company facts Founded | 14 October 2025 Founder | Moses Gitiriku Headquarters | Nairobi, Kenya Model | Donationware · free since Jul 2026 Products | 8 — Windows · Android · Node.js Telemetry to date | 0 bytes NAIROBI, KENYA · 1°17′S 36°49′E · EAT (UTC+3) Documentation ## Build on the offline stack. Every tool ships with documentation, signed releases and a public changelog. The SDK adds programmatic access to monitoring, refactoring and scanning — all local, all documented. Read the docs SDK reference - Product docs x2ydevs.xyz - SDK reference sdk.x2ydevs.xyz - npm package x2y-dev-tools-sdk - Release channel GitHub · signed - Current AV build v8.5.0 · Win 10/11 ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/ TITLE: Offline-First Products | x2y Devs Tools META DESCRIPTION: Explore eight offline-first x2y security and developer tools for Windows, Android and Node.js, with no accounts, no cloud dependency and zero telemetry. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products On this page Products Principles How to choose FAQ Documentation The complete suite # Eight tools. One principle: your machine is the boundary. Every x2y product is offline-first and account-free. Seven tools remain free, while Code Leak Detector is available under a one-time $29 licence. No telemetry, no cloud dependency, no compromises. Browse all products Read the docs 7 Products shipped 3 Platforms 0 B Telemetry collected $0 Suite price since Jul 2026 Filter All products Security Developer Windows Android Node.js ### x2y AV Ultimate v8.5.0 Security · Windows Comprehensive security suite for Windows. Real-time protection, threat intelligence with 5,500+ signatures from MalwareBazaar, URLhaus, OpenPhish and ClamAV, persistence auditing, network monitoring and an encrypted quarantine vault. Protects your system without slowing it down. - Dual-engine scanning on ClamAV 0.105 and YARA 4.5 - Persistence auditor for startup and registry analysis - Real-time network monitor with process mapping - SHA-256 and MD5 hash lookup, local quarantine WIN 10/11 5,500+ SIGS FREE View product Microsoft Store itch.io GitHub ### x2y Authenticator v1.0.0 Security · Android Offline by choice, secure by design. A high-security 2FA vault with Stealth Mode for duress protection, encrypted Panic Backups via Master QR, and a WiFi Companion that streams codes to your PC browser over the local network only. - 100% offline TOTP — no internet required ever - Stealth Mode with decoy vault for duress scenarios - PIN + biometric unlock via Android Keystore - Smart Folders, NTP sync, encrypted .x2y backup ANDROID STEALTH MODE FREE View product GitHub Uptodown APKPure ### Code Leak Detector v2.0.5 $29 ONE-TIME Security · Windows Scans your entire codebase for accidentally exposed secrets — API keys, tokens, passwords and credentials. 200+ detection patterns, entropy-based analysis, real-time file watching, and Gitleaks and TruffleHog rule set integration. Deep scan mode reaches into binaries and archives. - 200+ patterns plus entropy-based detection - Real-time file watcher with instant alerts - Gitleaks and TruffleHog rule integrations - SARIF and JSON export, pre-commit hook, learning mode WIN 10/11 200+ PATTERNS $29 ONE-TIME View product itch.io · $29 ### SiteDirective v2.0.0 Developer · Windows Professional-grade desktop crawler for web developers, SEO specialists and digital marketers. Full JavaScript rendering, multi-format sitemap generation (XML, HTML, JSON, TXT), a visual robots.txt architect, broken link detection and metadata audit — all processed locally. - Full JS rendering for SPA-aware crawling - XML, HTML, JSON and TXT sitemap export - Robots.txt architect with rule testing - Broken links, metadata and performance audit WINDOWS JS RENDERING FREE View product Microsoft Store itch.io ### x2y SDK v1.0.4 MIT Developer · Node.js Professional Node.js SDK combining API traffic monitoring, predictive issue analysis and intelligent code refactoring. Record API calls, predict failures before they happen, and get line-level suggestions for idiomatic, performant and modern async code. ES6 and CommonJS, TypeScript types included. - API traffic recording and predictive issue analysis - Code refactoring for strings and entire files - Performance, idiom and async pattern rules - Rate-limit detection, MIT licence, zero telemetry NODE 18+ ES6 + CJS MIT · FREE View product npm GitHub Docs ### x2y Extractor v2.1.0 Utilities · Windows Professional archive manager for Windows. Open, browse, extract, create, convert, split and merge archive files entirely offline. Full AES-256 password encryption for ZIP and 7Z, inline file previews, and support for 30+ formats including RAR, TAR, ISO, CAB and WIM. - AES-256 encryption for ZIP and 7Z archives - Inline previews for text, images and metadata - 30+ formats: ZIP, 7Z, RAR, TAR, ISO, CAB, WIM - Split and merge volumes, light and dark themes WIN 10/11 AES-256 FREE View product Microsoft Store itch.io ### x2y Devs Pad v2.0.0 Developer · Windows Professional text editor combining the simplicity of Windows Notepad with powerful tools for coding, scripting and managing text files. Command-line usage, file associations, syntax highlighting for 30+ languages, auto-save with a 5-version backup system, and advanced editing features. - CLI binary: x2ydevspad file.py:42 - Syntax highlighting for 30+ languages - Auto-save with 5-version backup retention - Regex find/replace, Go to Line, word wrap, zoom WINDOWS 30+ LANGUAGES FREE View product Microsoft Store itch.io Uptodown ### x2y GitIgnore Generator v1.0.0 Developer · Windows Never commit secrets again. Project-aware .gitignore generation with 20+ curated templates covering Node.js, Python, React, Rust, C++, macOS, VSCode and more. Audit existing repositories for dangerous exposures — .env files, credentials, build artifacts and editor swap files. - 20+ curated templates, bundled locally - Repository scanning for unignored sensitive files - Custom template creation, save, export and import - Atomic write with diff preview, copy to clipboard WINDOWS 20+ TEMPLATES FREE View product Microsoft Store itch.io Uptodown Shared principles ## Every product in the suite answers to the same three commitments ### Offline-first Every feature works without a network connection. If a capability cannot function offline, it does not ship. Signature bundles, template libraries, rule packs and rendering engines are embedded in the installer. ### Zero telemetry No analytics, no crash reports, no "help improve" prompts, no licence verification calls. Verified at 0 bytes collected across the entire suite since day one. Confirm with any network monitor. ### No accounts, ever Downloads require no sign-up. Licences do not phone home. Your copy is yours — online, offline, forever. The suite has been free since July 2026 under a donationware model. How to choose ## Start from the problem, not the product Eight tools, one architecture. Pick by the job in front of you — every page on this site states the version, the platform and the price, and none of them asks for an account. Which x2y Devs Tools product fits which problem If you need to… | Use | Platform | Price | Version Scan a Windows machine offline for malware | x2y AV Ultimate | Windows 10/11 | Free | v8.5.0 Keep 2FA codes off any server | x2y Authenticator | Android | Free | v1.0.0 Find secrets committed in a codebase | Code Leak Detector | Windows 10/11 | $29 one-time | v2.0.5 Map, render and audit a website without a SaaS | SiteDirective | Windows | Free | v2.0.0 Monitor API traffic and refactor code in Node.js | x2y SDK | Node.js 18+ | Free · MIT | v1.0.4 Open, create or encrypt any archive | x2y Extractor | Windows 10/11 | Free | v2.1.0 Edit a file fast, with syntax and backups | x2y Devs Pad | Windows | Free | v2.0.0 Write a .gitignore and audit what leaked | x2y GitIgnore Generator | Windows | Free | v1.0.0 Overlapping by design. GitIgnore Generator keeps sensitive paths out of a commit, Code Leak Detector finds what a rule missed, and the x2y SDK exposes both engines programmatically for CI. Nothing needs to talk to us for any of it to work. Suite questions ## What people ask before they download anything Are all x2y products really free? Seven of the eight are free for personal and commercial use under the donationware model adopted in July 2026. Code Leak Detector moved to a single one-time USD 29 licence on 1 September 2026 — no subscription, no seat management and no account. Free-period copies keep working. See the Terms of Use . Do I need an account, licence key or email address? No. Downloads need no sign-up, licences never phone home, and no product shows a first-run registration dialog. Your copy works online, offline and indefinitely. How can I check that nothing is uploaded? Run any product under Wireshark, GlassWire, mitmproxy or your operating system's firewall log and observe zero outbound connections attributable to the application. Every product page states its own data policy in a Security model section. Which platforms are supported? Windows 10 and 11 for the desktop tools, Android for x2y Authenticator, and Node.js 18+ for the x2y SDK. There is no iOS app, and Authenticator has no Windows vault — its WiFi Companion streams codes to a browser on your local network instead. Those limits are stated on the product pages rather than buried in a footnote. Where are releases published? Microsoft Store and itch.io for Windows installers, GitHub Releases with signed artefacts and SHA-256 checksums, Uptodown and APKPure as mirrors, and the npm registry for the SDK. Verify the checksum before installing anything. Can I use the tools in a company? Yes. All products may be used commercially, and the zero-telemetry design is usually what compliance and data-residency review latches on to: there is no processing to describe, because there is no processing. Security tooling for regulated environments is one of our named audiences. What happens to my data if x2y disappears tomorrow? Nothing changes on your machine. There is no service to shut down, no licence server to go dark and no sync to break. Signed installers, checksums and the MIT-licensed SDK stay usable, which is the point of offline-first software. Where do I read more before installing? The documentation holds installation steps, per-product references, the security model, the changelog and the support channels. Specific questions can go to support@x2ydevs.xyz . Ready to start ## Pick a tool, download it, and get to work No account. No telemetry. No cloud. Every product installs in seconds and runs entirely on your machine — with seven free tools and Code Leak Detector available under a one-time $29 licence. Browse on itch.io Read the documentation Suite summary Products | 7 tools Platforms | Windows · Android · Node.js Price | Free since Jul 2026 Telemetry | 0 bytes ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/av-ultimate/ TITLE: x2y AV Ultimate — Offline Windows Security Software META DESCRIPTION: x2y AV Ultimate is an offline Windows security suite with real-time protection, threat signatures, persistence auditing, network monitoring and quarantine. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / x2y AV Ultimate On this page Key features Threat sources Specifications Downloads Changelog Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Windows Security Software # x2y AV Ultimate v8.5.0 Comprehensive security suite for Windows. Real-time protection, threat intelligence with 5,500+ signatures, persistence auditing, and network monitoring. Protects your system without slowing it down. WINDOWS 10/11 5,500+ SIGNATURES 100% OFFLINE ZERO TELEMETRY Download free View on GitHub Free — no account, no subscription, no telemetry. Donationware since July 2026. At a glance - Version v8.5.0 - Platform Windows 10 / 11 · x64 - Engines ClamAV 0.105 + YARA 4.5 - Signatures 5,500+ offline bundle - Price Free · donationware - Telemetry 0 bytes Get it free Read the guide Signed installers with published SHA-256 checksums. No activation key, no account, no first-run prompt. Key features ## Everything you need to protect a Windows machine, nothing you don't ### Real-time threat detection Continuous monitoring of file system activity with instant detection and removal of malware, trojans, ransomware and potentially unwanted programs. Dual-engine scanning on ClamAV and YARA runs entirely in-process. ### Threat intelligence — 5,500+ signatures Offline signature bundles sourced from MalwareBazaar (recent and full feeds), URLhaus malicious URL detection, OpenPhish phishing protection, and the ClamAV freshclam database. Updated manually — the app never phones home. ### Persistence auditor Deep analysis of startup entries, registry run keys, scheduled tasks, services and browser extensions. Identifies persistence mechanisms used by malware to survive reboots — before they activate. ### Network activity monitor Real-time process mapping and traffic flow visualisation. See every active connection — protocol, remote address, PID, process name, state and risk level — at a glance. Export to CSV for forensic analysis. ### Quarantine vault Suspicious files are isolated in an encrypted local vault — not deleted, not uploaded. Review, restore or permanently remove at your discretion. Full audit trail of every quarantine action. ### Hash lookup — SHA256 / MD5 Compute and verify file hashes locally against known-good baselines. Integrity monitoring across 1,024+ watchpaths alerts on unexpected modification of binaries, configs and boot paths. Threat sources ## Open, auditable intelligence feeds #### MalwareBazaar RECENT + FULL FEEDS #### URLhaus MALICIOUS URL DETECTION #### OpenPhish PHISHING PROTECTION #### ClamAV FRESHCLAM DATABASE How threat intel works. All signature feeds are downloaded as offline bundles and shipped with each release. You can also update them manually from the original sources. The application itself never connects to MalwareBazaar, URLhaus, OpenPhish or ClamAV servers — verification is possible with any network monitor. Specifications ## Technical details x2y AV Ultimate specifications Product | x2y AV Ultimate Version | v8.5.0 Platform | Windows 10, Windows 11 Architecture | x64 (64-bit) Signatures | 5,500+ (offline bundle) Engines | ClamAV 0.105, YARA 4.5 Threat intel | MalwareBazaar, URLhaus, OpenPhish, ClamAV freshclam Watchpaths | 1,024+ integrity monitor paths Network monitor | Real-time TCP/UDP with process mapping Quarantine | Encrypted local vault, restorable Hash algorithms | SHA-256, MD5 Export | CSV (network connections, scan reports) Telemetry | 0 bytes — verified continuously Account required | None — ever Price | Free — donationware since Jul 2026 Developer | x2y Devs Tools Ltd, Nairobi, Kenya Quick start ### From download to protected in four steps - 01 #### Download and verify Get the installer from Microsoft Store, itch.io or GitHub. Verify the SHA-256 checksum against the published value. - 02 #### Install Run the signed installer. No administrator privileges required for standard installs. No account creation, no activation key. - 03 #### Load engines Signature bundles load from disk automatically. ClamAV and YARA initialise with 5,500+ offline signatures. The integrity monitor arms 1,024+ watchpaths. - 04 #### Scan and monitor Run a full scan, enable real-time protection, or open the Network Monitor. Every verdict is reached locally. Telemetry sent: 0 B. CLI x2y-av --scan C:\Projects --engines clamav,yara --report local resolving engines ............ clamav 0.105 · yara 4.5 loading signatures ........... 5,500+ · offline bundle integrity monitor ............ armed · 1,024 watchpaths network egress ............... blocked by design scanning 12,847 files ........ done in 41.2 s ✓ verdict: CLEAN · threats 0 · telemetry sent 0 B Downloads ## Get x2y AV Ultimate v8.5.0 Verify before installing. Every release is signed and accompanied by a published SHA-256 checksum. Compare the hash of your download against the value on the GitHub release page before running the installer. Microsoft Store PRIMARY · AUTO-UPDATES GitHub Releases v8.5.0 · SIGNED · CHECKSUM itch.io INSTALLER + PORTABLE Uptodown WINDOWS MIRROR APKPure WINDOWS MIRROR Changelog ## Release history MAR 2026 v8.5.0 Threat intelligence refresh to 5,500+ signatures. New persistence auditor module. Network activity monitor with real-time process mapping and traffic flow graph. Hardened installer with published SHA-256 checksums. DEC 2025 v7.0.0 New dual-engine detection pipeline (ClamAV + YARA). Integrity monitor with configurable watchpaths. Quarantine vault with encrypted local storage. OCT 2025 v6.x Initial public launch. Core scanning engine, basic threat detection, Windows 10/11 support. Security model ## Privacy enforced by architecture, not promises Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Data egress: none by design. Scan engines: ClamAV and YARA (open source). Threat intel: MalwareBazaar, URLhaus, OpenPhish (loaded offline). Updates: signed releases via GitHub with published SHA-256 checksums. Licence: free, donationware. Every claim above is independently verifiable. Run Wireshark, Fiddler, GlassWire, or your operating system's firewall logs while using x2y AV Ultimate. You will observe zero outbound connections attributable to the application. We encourage this verification. Security manifest Telemetry | 0 bytes collected Account | None required — ever Data egress | None by design Engines | ClamAV 0.105 · YARA 4.5 Threat feeds | Offline bundles only Quarantine | Encrypted local vault Installer | Signed · SHA-256 published Verification | Any network monitor Under the hood ## How x2y AV Ultimate reaches a verdict without a network connection ### Two engines, one local pipeline Every scan in x2y AV Ultimate is answered by two independent engines running in the same process. ClamAV 0.105 supplies the traditional signature match against bytecode and CVD-format databases; YARA 4.5 supplies the rule-based layer that catches families, packers and behavioural artefacts a hash list will never see. A file is only reported clean when both engines agree, and both engines read from bundles already on your disk. Because there is no query to send, verdict latency is the cost of reading a file — not the cost of a round trip. That matters on machines with slow or metered links, and it matters when the network is deliberately unavailable. ### What 5,500+ offline signatures actually means The shipped bundle combines ClamAV freshclam databases with curated samples from MalwareBazaar (recent and full feeds), malicious URL data from URLhaus and phishing indicators from OpenPhish. Those feeds are the same public sources commercial products index; the difference is delivery. Here they are downloaded as a bundle, pinned to a release and verified by checksum before the app loads them. The trade-off is honest and documented: offline signatures age. A commercial cloud scanner can answer a brand-new sample within minutes; x2y AV Ultimate answers once you refresh the bundle. For air-gapped or intermittently connected machines, that trade — a known, dated detection set you can audit, versus an opaque live one you cannot — is usually the right one. ### Persistence and integrity, not just files Malware survives reboots by writing itself into startup entries, registry run keys, scheduled tasks, services and browser extensions. The persistence auditor enumerates exactly those locations and shows what each entry points at, so a suspicious scheduled task is visible even when its payload is not yet detected by any engine. The integrity monitor watches 1,024+ configured watchpaths — binaries, boot paths and configuration files — and alerts on unexpected modification. Combined with local SHA-256 and MD5 hashing, that gives you a baseline you control rather than a reputation service you trust blindly. ### Quarantine you can audit Detections are not deleted and never uploaded. Objects are moved into an encrypted local vault with a full audit trail, so you can review, restore or permanently remove each one. Every action, verdict and engine response is also exportable as CSV for your own records or an incident timeline. How it works ## From installer to first verdict, entirely on your machine #### Verify, then install Download the signed installer from Microsoft Store, itch.io or GitHub Releases and compare its SHA-256 hash with the value published on the release page. Standard installs need no administrator privileges, and there is no activation step to complete. #### Engines load from disk ClamAV and YARA initialise against the offline signature bundle. The integrity monitor arms its watchpaths. No configuration wizard asks for an email address, a cloud region or permission to send samples. #### Scan on your terms Run a quick scan, a full scan or a custom scope such as a single project directory. Heuristics and both engines run in-process; results stream into the same view as the scan progresses. #### Act on verdicts locally Detections move to the encrypted quarantine vault with a timestamped entry in the audit trail. Clean verdicts, engine versions and per-file timings can be exported to CSV for reporting. Technical summary Detection path | ClamAV signature match → YARA rule match → heuristic verdict Signature load | Offline bundle, verified at startup Integrity baseline | 1,024+ watchpaths, alert on modification Quarantine | Encrypted local vault, restorable Reporting | CSV export of scans and network connections Update model | Manual bundle refresh, pinned per release Verify the silence yourself. Launch the app under Wireshark, GlassWire, mitmproxy or your Windows firewall log. There is no analytics endpoint, no crash uploader and no licence ping to find — the update path is a bundle you download on purpose. Who it is for ## Situations where an offline engine is the only kind that works Six environments we designed against, because a cloud-only scanner simply stops being useful in all of them. ### Air-gapped and restricted networks Labs, OT benches and government or finance workstations with no outbound path. The bundle is carried in on removable media and the app never expects to reach a vendor. ### Field laptops and travel A machine that spends weeks off a corporate network still gets a dated, auditable detection set instead of the degraded mode a cloud product falls back to. ### Small teams without an EDR budget Endpoint coverage for a studio, agency or NGO across a handful of Windows machines, with CSV exports that are good enough for an insurance or compliance review. ### Incident triage before you reimage The persistence auditor and integrity baseline tell you what changed and where a payload hides, so a rebuild decision is informed rather than hopeful. ### Release and build machines Scan a build tree before it ships. Verdicts come from engines whose versions you pinned, so results are reproducible across runs. ### Home machines you are responsible for A parent or partner setup where the goal is quiet protection: no upsell dialogs, no telemetry consent banners, no renewal notices. Prerequisites ## What your machine needs before the first scan x2y AV Ultimate specifications and prerequisites Requirement | Minimum | Recommended Operating system | Windows 10 (64-bit) | Windows 11 (64-bit) Architecture | x64 | x64 with an SSD for faster full scans Privileges | Standard install requires no administrator rights | Portable archive run from a user folder for kiosk or lab machines Network | None — the app is fully functional offline | A connection only to download the installer and a fresh signature bundle Other antivirus | Do not run two real-time scanners at once | Exclude the x2y quarantine folder from any remaining on-access scanner Storage | Room for the installer plus the offline signature bundle | Keep free space for scan caches and CSV reports you export Verification tools | Any SHA-256 hash utility | PowerShell Get-FileHash plus a network monitor to confirm zero egress Nothing here is a gate. There is no hardware requirement for a cloud lookups cache, no account to create and no minimum signature freshness enforced by the app. If you deliberately run an old bundle, the app still works — it just tells you what it was pinned to. Context ## How an offline scanner differs from the alternatives Three honest columns. Where x2y is weaker, the table says so. Comparison of local, cloud and built-in scanning approaches Capability | x2y AV Ultimate | Cloud subscription AV | Windows Defender only Detection source | Pinned ClamAV + YARA bundles you can inspect | Vendor cloud + local definitions, opaque | Microsoft definitions, opaque Behaviour offline | Full functionality | Degraded until definitions refresh | Full functionality Zero-day coverage | Weaker by design: relies on dated rules and heuristics | Strongest — live telemetry from millions of hosts | Strong — cloud-delivered protection Data egress | 0 bytes, verifiable | Samples, metadata and diagnostics per policy | Cloud lookups and automatic sample submission Account | None, ever | Vendor account usually required | Often tied to a Microsoft account Cost | Free · donationware | Recurring per-device subscription | Included with Windows Auditability | Open engines, published checksums, CSV exports | Closed engines | Closed engines Questions ## What people ask before they install Does x2y AV Ultimate replace Windows Defender? It is designed to be the scanner you control, not to win a detection-rate contest against a vendor with global telemetry. Run one real-time scanner at a time: if you enable x2y AV Ultimate, disable competing on-access protection so two filters do not fight over the same files. On-demand scanning of a specific folder is where this tool is strongest. Why only 5,500+ signatures when commercial products list millions? Because that number is a curated, offline, inspectable bundle rather than a marketing total of every hash in a cloud database. The bundle combines ClamAV freshclam data with MalwareBazaar samples, URLhaus malicious URLs and OpenPhish phishing indicators, and you can open it and read what is inside. Dated but auditable is a real trade-off, and we state it plainly. How do I update signatures without the app phoning home? Manually. Download the updated bundle from the release page, place it where the app expects it and restart. The application never connects to MalwareBazaar, URLhaus, OpenPhish or ClamAV servers on its own — that separation is the point of the design. Where do detected files go? Into an encrypted quarantine vault on your disk, never to us. Each entry records the verdict, the engine that raised it and the timestamp, and you can restore or permanently delete it. Nothing is uploaded for analysis because there is no upload path to analyse. Can I use it commercially? Yes. Since July 2026 every product in the suite except Code Leak Detector is free for personal and commercial use under a donationware model, with no seat limits and no licence keys. See the Terms of Use . Will it slow my machine down? Real-time work here is local file monitoring plus two engines running in-process, with no cloud round trip waiting in the scan path. Full scans are I/O bound, so an SSD and a sensibly scoped watchpath list matter more than CPU. You can also schedule scans for quiet hours. How do I check my download is genuine? Every release publishes a SHA-256 checksum on GitHub and itch.io. Run Get-FileHash .\x2y-av-ultimate-v8.5.0-setup.exe -Algorithm SHA256 in PowerShell and compare the output. If it differs, delete the file and report it to security@x2ydevs.xyz . Documentation ## Guides, sources and the release record Installation guide ../../docs/#installation · WINDOWS AV Ultimate reference Feature and spec walkthrough Security model Why egress is zero by design Microsoft Store PRIMARY · AUTO-UPDATES GitHub Releases v8.5.0 · SOURCE + CHECKSUMS Support Two working days, EAT (UTC+3) Read the changelog before you upgrade in bulk. Engine versions, signature bundle counts and installer changes are recorded on this page under Release history and in the suite changelog . Ready to protect your system ## Download x2y AV Ultimate — free, offline, forever No account. No subscription. No telemetry. Just comprehensive Windows security that works when the network is off. Get from Microsoft Store Download on itch.io Summary Version | v8.5.0 Platform | Windows 10 / 11 Price | Free — donationware Telemetry | 0 bytes More from the suite ## Pairs well with ### x2y Authenticator v1.0.0 · ANDROID · FREE ### Code Leak Detector v2.0.5 · WIN · $29 ONE-TIME ### x2y Extractor v2.1.0 · WIN · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/authenticator/ TITLE: x2y Authenticator — Offline 2FA Vault for Android META DESCRIPTION: x2y Authenticator is an offline Android 2FA vault with TOTP codes, Stealth Mode, encrypted Panic Backups, PIN, biometrics and a WiFi Companion. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / x2y Authenticator On this page Security features Convenience features Specifications Downloads Changelog Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Offline 2FA Vault for Android # x2y Authenticator v1.0.0 Offline by choice. Secure by design. A high-security offline 2FA vault with Stealth Mode, encrypted Panic Backups, and WiFi Companion for seamless desktop access. ANDROID 100% OFFLINE STEALTH MODE ZERO TELEMETRY Download free View on GitHub Free — no account, no cloud sync, no telemetry. Your secrets never leave your device. At a glance - Version v1.0.0 - Platform Android · APK - Protocol TOTP (RFC 6238) - Vault Android Keystore, encrypted - Price Free - Network permissions None for core use Download the APK Read the guide Codes are generated on-device from locally stored secrets. Nothing syncs, so there is nothing to breach on a server. Security features ## Built for threats that other authenticators ignore ### 100% offline — no internet required ever TOTP codes are computed entirely on-device using locally stored secrets and the system clock. The application has no network permissions and makes zero outbound connections. Airplane mode is the recommended operating environment. ### Stealth Mode with duress protection Configure a secondary PIN that opens a decoy vault populated with fake accounts. Under coercion, hand over the duress PIN — your real secrets remain invisible and inaccessible. The attacker sees a convincing but worthless vault. ### Encrypted Panic Backup with Master QR Export your entire vault as an encrypted backup protected by a master recovery key rendered as a QR code. Store the QR physically — in a safe, with a lawyer, split between trusted parties. Restore from it on any device running x2y Authenticator. ### PIN + Biometric authentication Unlock the vault with a numeric PIN, fingerprint, or both. Biometric data never leaves the Android Keystore — x2y Authenticator only receives a yes/no authorisation result from the hardware-backed secure enclave. Convenience features ## Security without the friction ### WiFi Companion — stream codes to PC browser Need a code on your desktop? The WiFi Companion securely streams TOTP codes from your phone to a PC browser over your local network. No cloud relay, no internet hop — the connection stays within your LAN and uses end-to-end encryption. ### Smart Folders — Work, Finance, Social Organise accounts into colour-coded categories. Switch between Work, Finance, Social and custom folders instantly. Each folder can have its own lock timeout and visibility rules. ### Restore via Master QR or .x2y file Two recovery paths: scan the Master QR code generated during Panic Backup setup, or import an encrypted .x2y backup file. Both methods restore the full vault with all accounts, folders and settings intact. ### NTP Time Sync for accurate codes TOTP codes depend on accurate time. x2y Authenticator optionally syncs against NTP servers to correct clock drift — the sync fetches only a timestamp, no personal data is transmitted, and it can be disabled entirely for air-gapped use. Specifications ## Technical details x2y Authenticator specifications Product | x2y Authenticator Version | v1.0.0 Platform | Android Protocol | TOTP (RFC 6238) Storage | On-device encrypted vault (Android Keystore) Sync | None by design — no cloud, no server Authentication | PIN + Biometric (fingerprint via Android Keystore) Stealth Mode | Duress PIN opens decoy vault with fake accounts Backup | Encrypted Panic Backup via Master QR or .x2y file Import | Manual secret entry, otpauth QR scan WiFi Companion | LAN-only encrypted stream to PC browser Folders | Work, Finance, Social + custom categories Time sync | Optional NTP (timestamp only, disableable) Network permissions | None required for core operation Telemetry | 0 bytes — verified continuously Account required | None — ever Price | Free Developer | x2y Devs Tools Ltd, Nairobi, Kenya Quick start ### From install to first code in four steps - 01 #### Install the APK Download from GitHub Releases, Uptodown or APKPure. Enable installation from unknown sources if prompted. Verify the SHA-256 checksum before installing. - 02 #### Set your PIN and biometric Create a vault PIN on first launch. Optionally enable fingerprint unlock. Configure a separate duress PIN for Stealth Mode if desired. - 03 #### Add accounts Scan an otpauth QR code from any service's 2FA setup page, or enter the secret manually. Assign each account to a Smart Folder (Work, Finance, Social). - 04 #### Create a Panic Backup Generate your encrypted Master QR recovery key. Store it physically — safe deposit box, sealed envelope, split between trusted parties. This is your lifeline if the device is lost. WiFi Companion setup. Open the Companion panel in x2y Authenticator, then visit the displayed local URL from any browser on the same network. Codes stream over an encrypted LAN connection — no internet, no cloud, no third party involved. Downloads ## Get x2y Authenticator v1.0.0 Verify before installing. Every release is signed and accompanied by a published SHA-256 checksum on the GitHub release page. Compare the hash of your downloaded APK before enabling installation. GitHub Releases v1.0.0 · APK · SIGNED Uptodown ANDROID · APK DOWNLOAD APKPure ANDROID · APK DOWNLOAD Changelog ## Release history MAR 2026 v1.0.0 Initial release. Offline TOTP vault with PIN and biometric authentication. Stealth Mode with duress PIN and decoy vault. Encrypted Panic Backup via Master QR and .x2y file. Smart Folders (Work, Finance, Social). WiFi Companion for LAN-only code streaming to PC browsers. NTP time sync (optional, timestamp only). Zero network permissions for core operation. Security model ## Your secrets exist in exactly one place: your device Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Cloud sync: none — by design. Secret storage: Android Keystore (hardware-backed where available). Network permissions: none required for core operation. Backup: encrypted locally, never transmitted. Licence: free. x2y Authenticator was designed around a single threat model: your secrets are safest when they exist in exactly one physical location that you control. There is no cloud copy to breach, no sync server to subpoena, no analytics pipeline to leak through. The WiFi Companion is the only feature that uses the network, and it operates exclusively within your local area network with end-to-end encryption — no packets leave your router. Security manifest Telemetry | 0 bytes collected Account | None required — ever Cloud sync | None — by design Secret storage | Android Keystore (hardware-backed) Network perms | None for core operation WiFi Companion | LAN-only, end-to-end encrypted Backup | Encrypted locally, never transmitted Duress protection | Stealth Mode with decoy vault Design notes ## Why an offline authenticator is a different security property ### The secret never has to leave the device x2y Authenticator implements time-based one-time passwords exactly as RFC 6238 defines them: a shared secret plus the current clock, hashed into a six-digit code. That computation needs no network, and adding one would only create an attack surface and a business decision about where your codes live. So there is no sync service, no recovery mailbox, no vendor database. If an authenticator app offers cloud backup, the honest question is not whether it encrypts the backup but who holds the key and what legal process can reach it. Here the answer is nobody but you. ### Sealed by the platform, not by a password Vault secrets are encrypted at rest using the Android Keystore, and unlock is gated by your PIN or fingerprint through the same hardware-backed path. The app asks for no permissions beyond local storage for the encrypted vault, and none at all for the core operation of producing codes. A passphrase-only vault is vulnerable while the device is unlocked; a Keystore-backed vault is not readable by another app on the same phone. That distinction is the whole reason this is a native Android app rather than a cross-platform wrapper. ### Stealth Mode and the duress scenario A duress PIN opens a decoy vault containing accounts you chose to expose. It is a real mitigation for a specific, unlucky situation — being forced to unlock your phone — and it is deliberately described as a mitigation, not a guarantee. An attacker who can compel you to give the real PIN still wins; Stealth Mode only removes the free look. We would rather under-promise here than sell you a magic button. The behaviour, the decoy setup and its limits are documented in the product reference . ### Panic Backup that you physically control Backups are encrypted and exported as a Master QR or a .x2y file. You decide whether that ends up in a safe, a bank deposit box or an encrypted drive. Losing the phone is survivable; losing both the phone and the backup is not — that is the cost of refusing to hold your recovery in our servers, and we think it is the right trade. ### WiFi Companion without a relay Typing six digits on a phone while a desktop login times out is the classic friction point. WiFi Companion streams the current code to a browser on the same local network over an encrypted LAN connection — no relay, no vendor server, and it can be switched off entirely. Similarly, optional NTP time sync requests a timestamp only, so codes stay accurate after a long flight; disable it and your clock drift is your own business. How it works ## From APK to first code in four moves #### Install and unlock Sideload the signed APK from GitHub Releases or take a mirror from Uptodown or APKPure. Set a PIN and enrol your fingerprint, which arms the Keystore-backed vault. #### Import an account Scan the service's standard otpauth:// QR code, or type the secret manually when a QR is unavailable — which is exactly how it should be, since the secret is then never photographed. #### Generate offline Codes compute on-device against the local clock. Airplane mode, a dead SIM and a locked-down network all change nothing. #### Back up deliberately Create an encrypted Panic Backup, print or store the Master QR, and test a restore on a second device before you ever need it. Technical summary Time-step | 30-second TOTP windows per RFC 6238 Secret storage | Android Keystore, encrypted at rest Unlock | PIN or fingerprint (biometric via Keystore) Duress path | Stealth Mode opens a decoy vault Backup | Encrypted Master QR or .x2y file Organising | Work, Finance, Social plus custom folders Test the recovery before you need it. Restore your backup onto a second device or a spare phone once. The one unrecoverable failure mode for any offline 2FA app is an encrypted backup nobody has ever successfully opened. Who it is for ## People who treat a second factor as a secret, not a convenience Six patterns where on-device TOTP is the correct architecture. ### High-value personal accounts Email, banking and domain registrars, where the attacker's realistic path is a breached cloud backup — a thing this app cannot be part of. ### Journalists and researchers Sources and accounts where a vendor-held vault is an attractive subpoena target. The vault lives on your device and nowhere else. ### Freelancers handling client systems Separate Work, Finance and Social folders keep client credentials organised and easy to remove from at handover time. ### Anyone in a coercive environment Stealth Mode with a duress PIN and decoy accounts, so a forced unlock reveals only what you intended to show. ### Travel and border crossings No account to disable remotely, no sync to suspend, and codes that keep working on a phone with the SIM removed. ### Desktop logins from a laptop WiFi Companion streams the current code to a browser on your LAN, so you are not squinting at a phone across a meeting table. Prerequisites ## What you need before you enrol your first account x2y Authenticator prerequisites Requirement | Minimum | Recommended Device | Android phone or tablet | A second Android device, so you can rehearse a restore Installation | Allow installation from an unknown source for the sideload, then turn it back off | Prefer the signed GitHub release over a mirror Hardware | PIN-capable device | Fingerprint or face unlock backed by the Android Keystore Clock | Reasonably accurate system time | Enable optional NTP sync if the device drifts, then disable it again Network | None for code generation | A local network only if you choose WiFi Companion Permissions | Local storage for the encrypted vault | Grant nothing else — the core flow needs no network permission Backup | An offline place for the Master QR or .x2y file | Print the QR and keep it physically separate from the phone Sideload deliberately. Verify the APK's SHA-256 checksum against the value on the GitHub release page before installing. If you would rather not manage signatures yourself, treat the backup — not the install channel — as the thing you must get right. Context ## Offline vault versus cloud-synced authenticator Both are usable. They fail in different ways, and you should pick knowingly. Comparison of on-device, cloud-synced and SMS second factors Property | x2y Authenticator | Synced authenticator app | SMS or app-push codes Where secrets live | Your device, Keystore-encrypted | Vendor cloud, encrypted to a key the vendor's process can reach | The carrier or the sending service Server-side breach impact | Nothing to breach | Depends entirely on the provider | SIM-swap risk sits with the carrier Recovery | You hold the only backup | Provider account recovery flow | Carrier or service support desk Offline behaviour | Works with the radio off | Usually cached, sync-dependent | Needs network or roaming Duress protection | Decoy vault behind a duress PIN | Not offered | None Cost | Free, no account | Free or subscription | Free to you, weak as a factor Questions ## The queries that decide whether to switch Can I back my codes up to Google Drive? No, and that is intentional. Cloud backup means a third party — and therefore any legal process aimed at that third party — sits between you and your second factor. Instead you get an encrypted export as a Master QR or a .x2y file, which you store the way you would store a hardware key. What happens if I lose my phone? You restore from your encrypted backup onto a replacement device using the Master QR or the .x2y file. If that backup is gone too, the services themselves must fall back to their own recovery codes, so keep those when you enrol anywhere. This is the price of a vault we cannot open for you. Is it safe if someone has my unlocked phone? Not entirely — nothing is, on an unlocked device. That is why unlock is gated by PIN or fingerprint through the Android Keystore, why the vault is encrypted at rest, and why accounts you consider critical belong in a folder you keep closed rather than on the launcher. Does it work in airplane mode? Yes. TOTP is arithmetic on a shared secret and the local clock, so airplane mode changes nothing. The only feature that needs a network is WiFi Companion, which is opt-in and LAN-only. Why is there no iOS build? Because the security model relies on the Android Keystore for hardware-backed secret storage and biometric gating, and we did not want to ship an iOS version that quietly weakens that guarantee. The Android app is the product; we would rather stay honest than be everywhere. Can I use it on Windows? The vault lives exclusively on the Android device. There is no Windows vault; the desktop path is WiFi Companion, which streams the current code to a browser over your local network. The documentation FAQ states this explicitly. What if I forget my PIN? There is no PIN recovery, for the same reason there is no cloud backup. Re-enrol each service with its own recovery path and restore future access from your encrypted backup. Treat the PIN as part of the key material, not as a login convenience. How is the 2FA secret added without a QR code? Add the account manually. Every standards-compliant service shows the base32 secret when you enrol; pasting it into the app is equivalent to scanning the QR, and it avoids photographing a secret. Documentation ## Guides, the APK and the safety checklist Authenticator reference Features, vault and duress mode Installation guide Android sideload step by step GitHub Releases v1.0.0 · SIGNED APK Uptodown mirror ANDROID · APK DOWNLOAD APKPure mirror ANDROID · APK DOWNLOAD Documentation FAQ Platform and recovery questions Two rules before you rely on it. First, move one low-stakes account, restore it onto a second device, and only then migrate your email and bank. Second, keep every service's own recovery codes offline — an offline vault and a service's recovery path must not live in the same drawer. Ready to go offline ## Download x2y Authenticator — your secrets, your device, forever No cloud. No sync. No account. Just a vault that answers to you alone — with Stealth Mode for when the stakes are highest. Get from GitHub Releases Download on Uptodown Summary Version | v1.0.0 Platform | Android Price | Free Telemetry | 0 bytes More from the suite ## Pairs well with ### x2y AV Ultimate v8.5.0 · WIN 10/11 · FREE ### Code Leak Detector v2.0.5 · WIN · $29 ONE-TIME ### x2y Devs Pad v2.0.0 · WIN · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/code-leak-detector/ TITLE: Code Leak Detector — Offline Secret Scanner for Windows META DESCRIPTION: Code Leak Detector scans Windows codebases for exposed API keys, tokens, passwords and secrets using 200+ patterns, entropy analysis, Gitleaks and TruffleHog. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / Code Leak Detector On this page Key features Advanced capabilities Specifications Downloads Changelog Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Scan & Detect Exposed Secrets in Code # Code Leak Detector v2.0.5 Desktop application that scans your entire codebase for accidentally exposed secrets — API keys, tokens, passwords, and other sensitive data. 200+ detection patterns with 100% offline processing. WINDOWS 10/11 200+ PATTERNS REAL-TIME WATCH ZERO TELEMETRY ONE-TIME LICENCE $29 — ONE-TIME PURCHASE -- Days -- Hours -- Minutes -- Seconds After 1 Sep 2026: one-time $29 licence. No subscriptions, no recurring fees, no account required. One-time purchase. No subscriptions, no recurring fees, no account required. Copies obtained during the free period continue to work indefinitely. Purchase — $29 View on itch.io At a glance - Version v2.0.5 - Platform Windows 10 / 11 · x64 - Rules 200+ offline patterns - Licence $29 one-time - Recurring fees None - Telemetry 0 bytes Buy the one-time licence Read the guide Copies obtained during the free period keep working. No account, no activation ping, no subscription. Key features ## Find secrets before they leave your disk ### 200+ detection patterns covering all major platforms AWS access keys, GitHub tokens, Slack webhooks, Stripe secret keys, Google API credentials, private RSA/EC keys, JWT secrets, database connection strings, npm tokens, PyPI credentials and hundreds more — all matched locally against an offline rule pack. ### 100% offline — no data leaves your machine Every scan runs entirely on your hardware. Source code, detected secrets, scan reports and rule packs never touch the network. There is no cloud analysis tier, no "send for deeper inspection" option, no telemetry pipeline. Verify with any network monitor. ### Real-time file watching with instant alerts Point the watcher at a working directory and receive instant notifications the moment a new secret is written to disk. Catch the leak at the keystroke — before it is staged, committed, or pushed to any remote. ### Entropy-based secret detection for custom patterns Beyond pattern matching, the entropy analyser flags high-randomness strings that look like secrets even when they do not match a known pattern. Catch obfuscated keys, rotated tokens and novel credential formats that rule-based scanners miss. Advanced capabilities ## Beyond pattern matching — enterprise-grade secret scanning ### Third-party scanner integrations (Gitleaks, TruffleHog) Run Gitleaks and TruffleHog rule sets alongside the native engine from a single interface. Combine detection strategies without leaving the application or managing separate toolchains. Results are merged, deduplicated and presented in a unified report. ### Deep scan mode for binaries and archives Secrets hide in compiled binaries, compressed archives and embedded resources. Deep scan mode unpacks ZIP, 7Z, TAR, GZ and JAR files in memory, inspects binary strings and extracts credentials that surface-level scanners never reach. ### Learning mode to manage false positives Mark a finding as a false positive and the learning engine suppresses identical patterns in future scans — per project, per file, or globally. The allowlist is stored locally and never shared. Tune the scanner to your codebase without losing coverage. ### Secure memory handling for sensitive data Detected secrets are held in protected memory regions and masked in every output — the UI, the report, the clipboard. Full values are never written to log files, temporary directories or swap. When the scan ends, the memory is zeroed. Specifications ## Technical details Code Leak Detector specifications Product | Code Leak Detector Version | v2.0.5 Platform | Windows 10, Windows 11 Detection patterns | 200+ (offline rule pack) Detection methods | Pattern matching + entropy analysis Integrations | Gitleaks, TruffleHog rule sets Deep scan | Binaries, ZIP, 7Z, TAR, GZ, JAR Real-time watch | File system watcher with instant alerts Learning mode | Per-project, per-file, global allowlists Reports | JSON, SARIF, CSV — CI-compatible Pre-commit | Supported via CLI hook Memory safety | Protected regions, zeroed on exit Processing | 100% local — no cloud relay Telemetry | 0 bytes — verified continuously Account required | None — ever Price | $29 one-time Developer | x2y Devs Tools Ltd, Nairobi, Kenya Quick start ### From install to first scan in four steps - 01 #### Install Download from itch.io. Run the installer — no administrator privileges required for standard installs. No account creation or subscription. Purchase once for $29. - 02 #### Point it at a repository Select a working tree, a specific path, or an entire drive. Choose standard or deep scan mode. Enable Gitleaks or TruffleHog rule sets if desired. The rule pack loads from disk — no network fetch. - 03 #### Review findings Findings appear in the dashboard with masked values, severity tags, file paths and line numbers. Use intelligent filtering to triage by risk level. Mark false positives to train the learning engine. - 04 #### Export and remediate Export the report as JSON, SARIF or CSV for your CI pipeline. Rotate exposed credentials immediately. Use the pre-commit hook to prevent future leaks from reaching version history. CLI cld scan ./repo --rules strict --format sarif indexing 1,204 files ......... done matching 200+ patterns ....... offline pack 2026-06 findings ..................... 2 (masked) src/deploy.ts:88 api_key ****…xyz123 [high] .env.bak token ****…9f41aa [med] ✓ report saved locally · cld-report.sarif · 0 B sent Downloads ## Get Code Leak Detector v2.0.5 One-time $29 licence. Code Leak Detector is a paid product. One-time purchase, no subscriptions, no recurring fees, no account required. Copies obtained during the free period continue to work indefinitely. itch.io $29 · v2.0.5 · ONE-TIME LICENCE Changelog ## Release history JUN 2026 v2.0.5 Expanded rule pack to 200+ detection patterns. Entropy-based secret detection for custom and obfuscated patterns. Gitleaks and TruffleHog rule set integration. Deep scan mode for binaries and compressed archives (ZIP, 7Z, TAR, GZ, JAR). Learning mode with per-project, per-file and global allowlists. Real-time file watcher with instant alerts. Secure memory handling with zeroed buffers on exit. SARIF and JSON report export for CI pipelines. Pre-commit hook support. 2026 v2.0.0 Report engine rewrite. Intelligent filtering by severity, file type and pattern category. Scan history with trend analysis across multiple runs. Masked value display in all outputs. CSV export added alongside JSON. 2025 v1.x Initial release. Core pattern-matching engine with 80+ rules. Basic scan and report workflow. Manual scan only — no file watcher. Security model ## Your source code and its secrets never leave your machine Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Source access: only directories you explicitly select. Detected secrets: masked in all outputs, held in protected memory, zeroed on exit. Rule packs: bundled locally, never fetched. Cloud analysis: none — every scan runs on your hardware. Licence: $29 one-time, with no subscription or recurring fee. Code Leak Detector reads the files you tell it to scan — that is its function. It does not transmit source code, detected secrets, scan reports, file paths, or any other data anywhere. The rule pack is embedded in the installer and exists entirely on your filesystem. Detected secrets are masked in every output surface — the dashboard, the report, the clipboard — and held in protected memory regions that are zeroed when the scan completes. There is no cloud analysis tier, no "send for deeper inspection" option, no analytics SDK, no crash reporter. Verify with Wireshark, Fiddler, GlassWire or your firewall logs — you will observe zero outbound connections. Security manifest Telemetry | 0 bytes collected Account | None required — ever Source access | Only directories you explicitly select Detected secrets | Masked in all outputs, zeroed on exit Rule packs | Bundled locally, never fetched Cloud analysis | None — all scans local Network | Zero outbound connections Verification | Any network monitor Detection model ## How a local scanner finds secrets without reading your code anywhere else ### Patterns are the fast path Most real leaks are boring: a provider key in the shape the provider documents. The offline rule pack ships 200+ patterns covering access tokens, refresh tokens, API keys, private key blocks, database URLs and service-account files, matched against file contents as the scan walks your tree. Because the rules are local and versioned, a finding is reproducible. The same repository, the same rule pack and the same exclusions produce the same report — which is exactly what you need if a scan is part of a release checklist or an audit. ### Entropy catches the rest Custom headers, in-house token formats and obfuscated constants do not match a known shape. For those, the scanner scores character entropy and structure — long, high-entropy strings assigned to variables named like credentials — and reports them separately as candidates rather than confirmations. That split matters operationally. Confirmed pattern hits should be treated as leaked. Entropy candidates are a review queue, and the tool is honest enough to label them that way. ### Gitleaks and TruffleHog rules, on your terms The scanner ingests Gitleaks and TruffleHog rule sets, so an organisation that standardised on either can align findings without changing tools. Nothing is delegated to those projects: matching runs in-process against the bundled packs. ### False positives are managed, not ignored Learning mode lets you suppress a finding per file, per project or globally, with the reason recorded. That is the difference between a scanner a team keeps using and one they disable after a week of test fixtures tripping on every commit. Secure memory handling closes the other half of the loop: matched values are masked in the interface and reports, protected regions are zeroed on exit, and candidate secrets are never written to a plaintext temporary file on the way to a report. How it works ## Scan a repository, review findings, wire it into the workflow #### Point it at a tree Choose a working directory, a folder of exports or a release artefact. The indexer enumerates files, skipping binary blobs unless deep scan is enabled. #### Match and score The 200+ pattern pack runs first, then entropy scoring over the remaining candidates. Deep scan opens binaries, JARs and compressed archives for the same treatment. #### Review masked findings Each hit shows the file, the line, the rule that fired, a severity and a masked value. Nothing sensitive needs to be on screen to decide whether it is real. #### Export and remediate Write JSON, SARIF or CSV. Pre-commit hooks and CI steps consume the same exit codes, so a new tracked secret can fail the commit rather than the release. Technical summary Scan modes | On-demand, scheduled watching, deep scan Watch mode | File-system watcher with instant alerts on new exposures Report formats | JSON · SARIF · CSV Hook support | Pre-commit, CI pipeline steps Suppression | Per-file, per-project and global allowlists Memory safety | Masked display, buffers zeroed on exit Finding a secret is the beginning, not the end. Rotating the credential is mandatory, because anything committed to a public repository should be treated as already collected. Then decide whether history needs rewriting — git rm --cached removes a file from tracking, not from previous commits. Who it is for ## Teams that cannot afford one careless commit Six situations where a local scanner earns its licence fee once. ### Agencies shipping client code Prove that a repository handed over clean stayed clean, with a dated SARIF report instead of a promise in an email. ### Pre-release and open-sourcing checks Flipping a private repository to public is the single most common way a project leaks. Scan before the toggle, and again in CI afterwards. ### Security and platform teams A desktop scanner your developers can run themselves beats a queue for the central tooling team, and never sees the source. ### Contractors and consultants One-time licence, no seat subscription. Scan a client repository on the client's machine, offline, in minutes. ### Archives, backups and old exports Deep scan reads inside ZIP, 7Z, TAR, GZ and JAR files, where abandoned credentials hide longest and are least likely to be rotated. ### Incident response and forensics When a repository may already be public, the scanner's job is to enumerate every candidate so your rotation list is complete rather than guessed. Prerequisites ## Environment, integrations and licence terms Code Leak Detector prerequisites and licence terms Requirement | Minimum | Recommended Operating system | Windows 10 (64-bit) | Windows 11 (64-bit) Target of a scan | A local folder or working tree | A Git working tree plus its checked-out artefacts, so build outputs get covered too Privileges | Standard user account | No service install needed; run it as the developer who owns the repository Network | None — every byte is processed locally | A connection only to download the installer and the rule-pack update CI usage | Reports consumed as artefacts | Pre-commit hook plus a pipeline gate using the same exit codes Existing scanners | Fine to run alongside Gitleaks or TruffleHog | Import their rule sets so findings converge instead of competing Licence | $29 one-time per licence | Reinstall and move machines freely — there is no activation server to phone Price changes are documented, not hidden. Code Leak Detector moved to a one-time $29 licence on 1 September 2026 after a free period; it has no subscription and no recurring charge, and every other product in the suite remains free. Context ## Local desktop scanner versus hosted and DIY options Where each approach genuinely wins. Comparison of local, hosted and scripted secret scanning Concern | Code Leak Detector | Hosted secret scanning | Regex in a build script Where code goes | Nowhere — in-process on your machine | Uploaded or indexed by the provider | Local, but you maintain the rules Rules maintenance | Versioned offline pack, importable third-party packs | Provider-managed and opaque | Whatever your team remembers to update Archives and binaries | Deep scan inside ZIP, 7Z, TAR, GZ, JAR | Usually source files only | Rarely handled Finding shape | Confirmed hits plus entropy candidates | Provider severity model | Whatever your regex matches Blocking a commit | Pre-commit hook with exit codes | Platform-dependent, needs account/API | Possible, fully yours to break Cost | $29 one-time (the suite's only paid tool) | Often per-seat SaaS | Engineering hours Questions ## Answers that decide the purchase Does my source code leave my machine? No. Detection runs in-process against the bundled rule packs, with no cloud relay and no vendor endpoint to call. The report you export is the only artefact the tool produces, and it goes wherever you put it. That is verifiable: run the scanner under any network monitor and watch it stay silent. Is the licence perpetual, and what does it cover? It is a one-time $29 licence with no subscription, no recurring fee and no account required. Copies obtained during the free period continue to work indefinitely. Full terms are in the Terms of Use . Does it scan Git history? It scans what is on disk — working trees, build output, exports and archives. For history you should combine it with your own repository review: anything already committed is presumed public, so rotation matters more than archaeology. Does it replace GitHub's or my forge's secret scanning? No, and it does not try to. Push-time scanning on a forge only sees the moment a secret arrives; it does not audit the whole tree, archives or a repository you are about to open source. Treat them as independent layers — a local scan is also the only option for repositories that never touch a hosted forge. Which secret types does it detect? 200+ patterns covering all major cloud providers, SaaS platforms, private key blocks, database connection strings and service-account files, plus entropy-based scoring for custom and uncommon formats. Gitleaks and TruffleHog rule sets can be imported if your team already standardised on them. How do I stop test fixtures tripping every scan? Learning mode. Suppress a finding per file, per project or globally, with the reason recorded, so legitimate sample keys stop producing noise without hiding a real credential in a different location. Can it run in CI? Yes — the same report formats (JSON, SARIF, CSV) and exit codes work as a pipeline gate, and SARIF is consumed natively by the common code-scanning dashboards. Pre-commit hooks cover the local half of that. What should I actually do when it finds something? Rotate first, then remove, then verify. Revoke and reissue the credential, take it out of the file, and remember that git rm --cached untracks a file without erasing previous commits. If the repository was ever public or shared, assume the secret is known. Documentation ## Guides, report formats and support Product reference Detection modes and integrations Installation guide Windows install and verification Changelog Rule-pack and engine history itch.io store page v2.0.5 · INSTALLER Licence terms What $29 one-time means Talk to us first Evaluation and site licences Free-period copies are unaffected. If you installed Code Leak Detector while it was donationware, it keeps working — the licence change applies to purchases from 1 September 2026 onward. Ready to scan ## Purchase Code Leak Detector — $29 one-time No subscriptions. No recurring fees. No account. One payment, permanent licence. Find exposed credentials at the keystroke — entirely on your machine. Purchase — $29 Summary Version | v2.0.5 Platform | Windows 10 / 11 Price | $29 one-time Telemetry | 0 bytes More from the suite ## Pairs well with ### GitIgnore Generator v1.0 · WIN · FREE ### x2y Devs Pad v2.0.0 · WIN · FREE ### x2y AV Ultimate v8.5.0 · WIN 10/11 · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/site-directive/ TITLE: SiteDirective — Sitemap Generator & SEO Crawler META DESCRIPTION: SiteDirective is a local Windows sitemap generator and SEO crawler with JavaScript rendering, robots.txt tools, broken-link detection and metadata audits. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / SiteDirective On this page Core features SEO analysis Specifications Downloads Changelog Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Professional Sitemap Generator & SEO Crawler # SiteDirective v2.0.0 A professional-grade desktop application for web developers, SEO specialists, and digital marketers. Built as a high-performance crawling engine, it automates website structure discovery to generate search engine-compliant XML, HTML, JSON, and TXT sitemaps. WINDOWS JS RENDERING 100% LOCAL ZERO TELEMETRY Download free View on itch.io Free — no account, no cloud processing, no telemetry. Every crawl runs entirely on your machine. At a glance - Version v2.0.0 - Platform Windows 10 / 11 - Rendering Full JS engine, SPA-aware - Sitemaps XML · HTML · JSON · TXT - Crawl depth 1–10 levels - Price Free · 0 bytes out Download free Read the guide Crawls, renders and audits run on your machine. Results export as sitemaps and CSV — nothing is sent to a vendor. Core features ## A crawling engine built for real-world websites ### Full website crawling with JS rendering Most crawlers see only static HTML. SiteDirective uses a real browser rendering engine to execute JavaScript, wait for dynamic content to load, and discover URLs that only appear after client-side hydration. Single-page applications, React, Vue, Angular — all fully indexed. ### XML, HTML, JSON, TXT sitemap generation Export sitemaps in every format search engines accept. XML for Google and Bing submission, HTML for human-readable site maps, JSON for API-driven workflows, and plain TXT for lightweight indexing. All generated locally from live crawl data. ### Robots.txt Architect with custom rules Build, preview and validate robots.txt files with a visual rule editor. Define user-agent directives, allow/disallow patterns, crawl-delay values and sitemap references. Test rules against your crawled URL set before deploying. ### Crawl Depth Control (1–10 levels) Set exactly how deep the crawler goes — from a single landing page (depth 1) to a full site traversal (depth 10). Combine with URL pattern filters to scope crawls precisely. Throttle request rate to respect server resources and avoid rate limiting. SEO analysis ## Audit every page before search engines do ### Broken Link Detection (404 errors) Every internal and external link is checked during the crawl. Dead links are flagged with their source page, anchor text and HTTP status code. Export the full report to prioritise fixes before they hurt your search rankings. ### Metadata Audit (missing titles and descriptions) Scan every crawled page for missing, duplicate or truncated title tags and meta descriptions. Identify pages with no H1 heading, multiple H1s, or missing canonical URLs. Colour-coded severity makes triage fast. ### Performance Flagging (heavy pages) Pages with excessive response times, oversized payloads or slow server responses are flagged automatically. Identify the pages dragging down your Core Web Vitals before Google does it for you. ### 100% local processing, zero telemetry Every crawl runs on your machine. Crawled data, sitemaps, audit reports and robots.txt files are stored locally and never transmitted. No analytics, no crash reports, no cloud relay. Verify with any network monitor. Specifications ## Technical details SiteDirective specifications Product | SiteDirective Version | v2.0.0 Platform | Windows Rendering | Full JavaScript engine (SPA-aware) Sitemap formats | XML, HTML, JSON, TXT Crawl depth | 1–10 levels configurable Robots.txt | Visual architect with rule testing Broken links | Internal + external 404 detection Metadata audit | Titles, descriptions, H1, canonicals Performance | Response time and payload flagging Rate control | Configurable request throttle URL filtering | Include/exclude patterns Export | Sitemaps, CSV audit reports Processing | 100% local — no cloud relay Telemetry | 0 bytes — verified continuously Account required | None — ever Price | Free Developer | x2y Devs Tools Ltd, Nairobi, Kenya Quick start ### From install to first sitemap in four steps - 01 #### Install Download from Microsoft Store or itch.io. Run the installer — no administrator privileges required for standard installs. No account creation, no activation key. - 02 #### Configure the crawl Enter the root URL. Set crawl depth (1–10), enable or disable JS rendering, configure request throttle and add URL include/exclude patterns to scope the crawl. - 03 #### Crawl and analyse SiteDirective discovers URLs, renders JavaScript, checks every link and audits metadata. Review the results table — status codes, response times, titles, SEO flags — all in real time. - 04 #### Export and deploy Generate sitemaps in XML, HTML, JSON or TXT. Build a robots.txt with the visual architect. Export audit reports as CSV. Everything saves locally — upload to your server when ready. JS rendering note. Enabling JavaScript rendering uses a bundled browser engine and increases memory usage during the crawl. For large sites, start with a shallow depth (2–3) and increase once you have confirmed the crawl scope is correct. Downloads ## Get SiteDirective v2.0.0 Verify before installing. Every release is signed. Compare the published checksum on the release page against your downloaded file before running the installer. Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Changelog ## Release history 2026 v2.0.0 Major release. Full JavaScript rendering engine for SPA-aware crawling. Robots.txt Architect with visual rule editor and testing. Multi-format sitemap export (XML, HTML, JSON, TXT). Broken link detection for internal and external URLs. Metadata audit covering titles, descriptions, H1 and canonicals. Performance flagging for heavy pages. Crawl depth control (1–10 levels). Configurable request throttling and URL pattern filtering. 2025 v1.x Initial release. Basic sitemap generation from static HTML crawling. XML export. Simple URL discovery without JavaScript rendering. Security model ## Your crawl data never leaves your machine Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Crawl data: stored locally only. Sitemaps and reports: saved to your filesystem, never transmitted. Cloud processing: none — the crawl engine runs entirely on your hardware. Licence: free. SiteDirective makes outbound HTTP requests to the websites you choose to crawl — that is its function. It makes zero other network connections. No analytics endpoint, no crash reporter, no licence verification server, no "improve this product" telemetry. The crawled data, generated sitemaps, audit reports and robots.txt files are written to your local filesystem and exist nowhere else. Verify with Wireshark, Fiddler, GlassWire or your firewall logs. Security manifest Telemetry | 0 bytes collected Account | None required — ever Crawl data | Stored locally only Sitemaps | Saved to filesystem, never transmitted Cloud processing | None — engine runs on your hardware Outbound traffic | Only to crawled target sites Verification | Any network monitor Crawling properly ## The difference between a URL list and an understanding of a site ### Rendering is the whole game A static fetch sees the HTML shell of a client-rendered application: nav links that exist only after hydration, routes that never appear in markup, and menus built by a router. Crawl that and you conclude a site is a fraction the size it is. SiteDirective drives a full JavaScript engine, so it sees what a browser sees — including content injected after load — and records the status code and payload that a real visitor would. Depth control (1 to 10 levels) and include/exclude URL patterns keep large sites tractable without giving up rendering. ### Throttling is courtesy, and it is configurable A crawler without a throttle is a denial-of-service test on your own staging box. Request throttling, depth limits and pattern filters exist so a crawl is sized to what the server can take, and so the results describe your site rather than the artefacts of a hammered environment. This is also the right way to treat robots.txt: read it, respect it, and use the built-in architect to author rules you have actually tested before you deploy them. ### Four sitemap formats, chosen on purpose XML is what search engines consume, so it is the default export. HTML sitemaps serve people and give crawlers a link graph that does not depend on a file path. JSON suits programmatic pipelines and static-site generators; TXT is the quick inventory for a review or a handover. Because they come from the same crawl, the four cannot drift out of sync with each other — the failure mode of hand-maintained sitemap files. That single-source behaviour is most of the value of the tool. ### The audit is a checklist you can prove Broken-link detection covers internal and external 404s; the metadata audit flags missing or duplicate titles and descriptions, absent H1s and canonical mismatches; performance flagging identifies heavy pages by response time and payload. These are the same checks we run against this site before a release. An offline crawler is not a Search Console replacement — it has no idea what a search engine decided to index — but it is the cheapest way to catch a broken template, a missing canonical or an orphaned route before anybody else does. ### Where crawl data goes: nowhere Crawled URLs, response bodies, audit findings and exports stay on the machine that ran the crawl. There is no vendor cloud receiving your pre-launch site, your staging credentials or your client's structure. For agencies, that is a contractual point as much as a privacy one: the crawl of a client's unreleased site is confidential data, and a hosted SEO platform stores it somewhere you did not choose. How it works ## Configure a crawl, get publishable artefacts #### Point at a root URL Set the start address, choose a crawl depth between 1 and 10 and add include or exclude patterns so a marketing site is not swallowed by its own documentation subfolder. #### Crawl and render The engine fetches each URL, renders JavaScript, records status codes and response times, and builds the link graph. Throttle to protect the target while it works. #### Audit what it found Review broken internal and external links, metadata gaps, canonical mismatches and heavy pages from the same crawl — no second pass, no re-fetch. #### Export and deploy Write the XML, HTML, JSON or TXT sitemap plus a CSV audit report. Validate against a live search-console submission once deployed; a local crawl proves structure, not index coverage. Technical summary Rendering | Full JavaScript engine, SPA routes included Crawl scope | Depth 1–10, include and exclude patterns Etiquette | Configurable request throttling robots.txt | Visual architect with rule testing Audits | Links, metadata, canonicals, performance Exports | XML · HTML · JSON · TXT sitemaps, CSV reports Test a staging site, keep the robots rules honest. Run SiteDirective against an environment that blocks crawlers with noindex and a restrictive robots.txt, confirm the crawl respects both, and only then point it at production. A crawler that cannot be tamed by those files will annoy every server it ever touches. Who it is for ## Crawl jobs that need to stay on your machine ### SEO specialists and agencies Audit a client site before and after a migration, and hand over the CSV report without the crawl itself living on a vendor's server. ### Front-end and platform teams Catch orphaned routes, broken internal links and missing metadata in a SPA build before it ships. ### Marketing teams on static hosts Generate the XML and HTML sitemaps your host expects, from a local crawl, with no third-party account in the loop. ### Documentation and knowledge bases Large doc trees are exactly where depth limits and URL filters pay for themselves — and where hand-maintained sitemaps drift. ### Pre-launch QA Verify canonicals, titles, H1s and status codes on staging, while the site is still nobody's problem but yours. ### Performance triage Heavy-page flagging and response times from the same crawl point at the templates worth optimising, without installing an agent. Prerequisites ## Crawl sizing, etiquette and environment SiteDirective prerequisites and crawl sizing Requirement | Minimum | Recommended Operating system | Windows 10 | Windows 11 Target access | A URL the machine can reach | Include staging hosts that resolve only on your network or VPN Crawl budget | Depth 1–2 for a quick inventory | Depth 3–5 with include and exclude patterns for a real audit Throttling | Any value above the default concurrency | Throttle down for staging, small VPS or shared servers Rendering | On for static HTML sites too, to confirm parity | Always on for SPAs and any client-rendered route Output | Local disk for sitemaps and CSV exports | Version the generated XML in your repository so it is reviewable Privileges | Standard user account | No service, scheduler or background agent is installed A crawl is a request load. Size depth and throttle to the server you are hitting, respect robots.txt , and never crawl a production site you do not own without permission. The tool gives you the controls; the judgement stays with the operator. Context ## Desktop crawler versus hosted SEO platforms and curl scripts Comparison of local, hosted and scripted crawling Concern | SiteDirective | Hosted SEO platform | Ad-hoc script Where crawl data sits | Your machine | Vendor cloud, per retention policy | Your terminal scrollback Cost | Free | Monthly per-project subscription | Engineering hours JavaScript rendering | Full engine, SPA-aware | Usually included in higher tiers | You build it Works against staging or offline | Yes, including localhost | Often blocked by plan tier or public-URL requirement | Yes, if you write it robots.txt authoring | Built-in architect with rule testing | Report-only in most tools | You parse it Scheduling | On demand from the desktop app | Recurring crawls | You own the cron Historical trend dashboards | Not the purpose; export and diff CSVs | Built in | Not the purpose Questions ## The ones that come up in the first crawl Does SiteDirective obey robots.txt while crawling? Yes, and the point is to let you see what those rules do before search engines find out. Read the directives, confirm the crawl respects them, then use the Robots.txt Architect to compose rules and test them against your own URL list. Does it render JavaScript? My site is a React or Vue SPA. That is the main reason this is a rendering crawler rather than an href harvester. A full JavaScript engine executes the page, so client-rendered routes and content appear in the crawl the same way a browser would find them. Can I crawl localhost or a staging site? Yes — being a desktop app, it crawls anything your machine can reach, including localhost and hosts that resolve only on your network or VPN. Nothing needs to be publicly accessible first, which is what makes pre-launch auditing possible. Which sitemap formats does it export? XML for search engines, HTML for people and link discovery, JSON for pipelines and static-site tooling, and TXT for inventories and handovers. All four derive from one crawl, so they cannot disagree with each other. Does it upload my crawl? No. Crawled URLs, response data and audit findings are processed and stored locally; exports are files you choose to create and where you choose to put them. There is no cloud relay, and no account to attach the results to. Is it a replacement for Search Console? No, and it would be a lie to say so. Search engines tell you what they actually indexed; SiteDirective tells you what is structurally there and what a crawler will find. Use the desktop audit to fix the site, then confirm the outcome in your webmaster tools once it is live. Will it slow down or overload the target server? Only if you let it. Request throttling, depth limits and URL filters exist to size a crawl to the environment. For a small VPS or a staging box, start with shallow depth and an aggressive throttle and increase from there. Can I compare two crawls over time? Export the audit as CSV and diff it, or keep each generated sitemap under version control in your repository. There is no hosted history or trend dashboard — the artefacts are files you own, which is the trade we chose deliberately. Documentation ## Guides, downloads and the release record SiteDirective reference Crawl options and exports Installation guide Windows install and verification Security model Why crawl data stays local Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Our own sitemap The file this site ships Then go and fix the findings. Titles, descriptions, canonicals and breadcrumbs on this site are generated and checked with the same checklist SiteDirective runs — see Privacy for the no-tracking commitments behind our own crawl-friendly files, and the changelog for engine changes. Ready to crawl ## Download SiteDirective — map, audit and export, entirely offline No cloud processing. No account. No telemetry. Just a high-performance crawler that renders JavaScript, finds broken links and generates compliant sitemaps — all on your machine. Get from Microsoft Store Download on itch.io Summary Version | v2.0.0 Platform | Windows Price | Free Telemetry | 0 bytes More from the suite ## Pairs well with ### x2y AV Ultimate v8.5.0 · WIN 10/11 · FREE ### Code Leak Detector v2.0.5 · WIN · $29 ONE-TIME ### GitIgnore Generator v1.0 · WIN · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/sdk/ TITLE: x2y SDK — Node.js API Monitoring & Code Refactoring META DESCRIPTION: x2y SDK is a zero-telemetry Node.js toolkit for API traffic monitoring, predictive issue analysis and intelligent code refactoring, with ES6 and CommonJS support. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / x2y SDK On this page Overview Key features Installation Basic usage API monitoring Code refactoring Integration Specifications Downloads Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Professional SDK for API Monitoring & Code Refactoring # x2y SDK v1.0.4 MIT A comprehensive solution for modern software development, combining powerful API monitoring capabilities with intelligent code refactoring. Designed for developers who want to improve their API integration practices and code quality through automated analysis and suggestions. NODE.JS 18+ ES6 + COMMONJS TYPESCRIPT ZERO TELEMETRY npm install npm package GitHub Free & open source — MIT licence. No account, no telemetry, no cloud dependency. x2y-sdk · live examples Monitor Refactor Configure module: monitor runtime: node:22 telemetry: 0 B At a glance - Version v1.0.4 · stable - Package x2y-dev-tools-sdk - Runtime Node.js 18+ · ESM + CJS - Modules monitor · refactor · secrets · audit - Licence MIT — free & open source - Telemetry 0 bytes Install from npm API reference Zero postinstall scripts, no native dependencies and no vendor endpoint — observable from your own process. Overview ## API intelligence and code quality in one package The x2y SDK is a comprehensive solution for modern software development, combining powerful API monitoring capabilities with intelligent code refactoring. It is designed for developers who want to improve their API integration practices and code quality through automated analysis and suggestions. With support for both CommonJS and ES6 modules, the x2y SDK integrates seamlessly into any JavaScript or TypeScript project, providing real-time insights into API behaviour and actionable code improvement recommendations — all processed locally, with zero telemetry. SDK at a glance Package | x2y-dev-tools-sdk Version | v1.0.4 Runtime | Node.js 18+ Modules | ES6 + CommonJS Types | TypeScript definitions included Licence | MIT Telemetry | 0 bytes Key features ## Six capabilities, one import ### API Traffic Monitoring Record and analyse API calls with detailed metrics — endpoint, method, response time, status code and headers — stored entirely in memory or on your filesystem. ### Predictive Issue Analysis Anticipate API failures before they happen. The SDK analyses recorded traffic patterns to surface risk levels, rate-limit proximity and suggested fallback endpoints. ### Code Refactoring Suggestions Get intelligent, line-level suggestions to improve code quality — idiomatic patterns, performance fixes and modern async conversions — for strings or entire files. ### Performance Optimization Identify and fix performance bottlenecks like DOM queries inside loops, repeated allocations and unbatched operations. Suggestions include the corrected code, not just a warning. ### Async Pattern Improvements Modernise legacy promise chains into clean async/await syntax. The SDK detects nested .then() patterns and produces the equivalent await-based rewrite. ### Rate Limit Detection Monitor x-ratelimit-remaining and related headers across every recorded call. Predict when a limit will be reached and receive proactive warnings before requests start failing. Installation ## Three ways to get started NPM (Project) NPM Global GitHub (Source) npm install x2y-dev-tools-sdk npm install -g x2y-dev-tools-sdk git clone https://github.com/x2yDevs/x2y-sdk.git cd x2y-sdk npm install npm run build Import & setup ### ES6 or CommonJS — your choice The SDK ships with both module formats and bundled TypeScript definitions. Import whichever style your project uses and initialise with a single constructor call. JavaScript // ES6 modules import { X2YSdk } from 'x2y-dev-tools-sdk' ; // CommonJS (Node.js) const { X2YSdk } = require ( 'x2y-dev-tools-sdk' ); // Initialize the SDK const sdk = new X2YSdk (); Basic usage ## Record, predict and refactor in one flow JavaScript import { X2YSdk } from 'x2y-dev-tools-sdk' ; const sdk = new X2YSdk (); // Record API traffic sdk. recordAPITraffic ({ endpoint: '/api/users' , method: 'GET' , timestamp: Date . now (), responseTime: 200 , statusCode: 200 , headers: { 'x-ratelimit-remaining' : '85' } }); // Predict issues const prediction = await sdk. predictAPIIssues ( '/api/users' ); console . log (prediction); // Refactor code const suggestions = await sdk. refactorCode ( ` for (let i = 0; i < arr.length; i++) { console.log(arr[i]); } ` ); console . log (suggestions); API monitoring ## Record traffic, predict failures, configure thresholds #### Recording API traffic Build a dataset by recording API traffic data for predictions. Each call captures endpoint, method, timestamp, response time, status code and headers — the raw material the prediction engine learns from. JavaScript sdk. recordAPITraffic ({ endpoint: '/api/users' , method: 'POST' , timestamp: Date . now (), responseTime: 250 , statusCode: 201 , headers: { 'x-ratelimit-remaining' : '45' , 'x-ratelimit-limit' : '100' , 'content-type' : 'application/json' } }); #### Predicting API issues The SDK analyses recorded traffic to predict potential problems — risk level, rate-limit proximity, suggested fallback endpoints and a confidence score — before the next call is made. JavaScript const prediction = await sdk. predictAPIIssues ( '/api/users' ); console . log (prediction); /* Output: { endpoint : '/api/users' , riskLevel : 'medium' , predictedFailure : false , rateLimitApproaching : true , suggestedAlternatives : [ '/api/v2/users' , '/api/users?cached=true' ], confidence : 85 } */ #### Configuration options Customise SDK behaviour with two configuration objects — one for API monitoring, one for refactoring. Every value has a sensible default; override only what you need. JavaScript const sdk = new X2YSdk ( { // API monitoring config rateLimitThreshold: 80 , // Percentage before warning predictionWindow: 60000 , // Time window in ms apiUrl: 'https://api.example.com' }, { // Refactoring config targetLanguage: 'typescript' , rules: [ 'performance' , 'idiom' , 'async' ] } ); Code refactoring ## From strings to files — five ways to improve your code #### Refactoring code strings Analyse any code snippet and receive structured improvement suggestions — type, description, original code, suggested replacement, line number and severity. JavaScript const suggestions = await sdk. refactorCode ( ` for (let i = 0; i < arr.length; i++) { console.log(arr[i]); } ` ); console . log (suggestions); /* Output: [ { type : 'idiom' , description : 'Use array methods like forEach() for better readability' , originalCode : 'for (let i = 0; i < arr.length; i++) { ... }' , suggestedCode : 'arr.forEach(item => console.log(item));' , line : 2 , severity : 'medium' } ] */ #### Refactoring entire files Point the SDK at a JavaScript or TypeScript file on disk and receive a full list of suggestions across the entire source — ready to feed into a review workflow or CI gate. JavaScript const fileSuggestions = await sdk. refactorFile ( './src/example.js' ); console . log ( `${fileSuggestions.length} suggestions found` ); #### Performance suggestions Identify performance issues like DOM queries inside loops. The SDK suggests hoisting the query outside the iteration and provides the rewritten code block. JavaScript const performanceCode = ` for (let i = 0; i < items.length; i++) { document.getElementById('myElement').innerHTML += items[i]; } ` ; const suggestions = await sdk. refactorCode (performanceCode); // Will suggest caching the DOM query outside the loop #### Idiom suggestions Get recommendations for modern JavaScript and TypeScript idioms — replacing imperative loops with declarative array methods, eliminating var , and adopting optional chaining where appropriate. JavaScript const oldCode = ` var result = []; for (var i = 0; i < items.length; i++) { if (items[i].active) { result.push(items[i].name); } ` ; const suggestions = await sdk. refactorCode (oldCode); // Will suggest: items.filter(item => item.active).map(item => item.name) #### Async pattern improvements Modernise legacy promise chains into clean async/await syntax. The SDK detects nested .then() structures and emits the equivalent await-based control flow. JavaScript const oldAsyncCode = ` fetch('/api/data') .then(response => response.json()) .then(data => console.log(data)) .catch(error => console.error(error)); ` ; const suggestions = await sdk. refactorCode (oldAsyncCode); // Will suggest using async/await instead of promise chains Integration ## Wrap fetch once, monitor everything Monkey-patch window.fetch (or the Node equivalent) to automatically record every outbound request, measure its duration, and run a prediction before returning the response. High-risk endpoints surface a console warning without interrupting the call. Auto-refactoring. Set the environment variable X2Y_AUTO_REFACTOR=true to automatically apply high-severity refactoring suggestions during a build step. Use with caution in production pipelines — review the diff first. JavaScript const originalFetch = window .fetch; window .fetch = async (...args) => { const start = Date . now (); const response = await originalFetch (...args); const duration = Date . now () - start; // Record the traffic sdk. recordAPITraffic ({ endpoint: args[ 0 ]. toString (), method: 'GET' , timestamp: Date . now (), responseTime: duration, statusCode: response.status, headers: Object . fromEntries (response.headers. entries ()) }); // Predict if next calls might fail const prediction = await sdk. predictAPIIssues (args[ 0 ]. toString ()); if (prediction.riskLevel === 'high' ) { console . warn ( 'High risk detected for:' , args[ 0 ]); } return response; }; Specifications ## Technical details x2y SDK specifications Package | x2y-dev-tools-sdk Version | v1.0.4 Runtime | Node.js 18+ Module formats | ES6 + CommonJS TypeScript | Bundled type definitions API monitoring | Traffic recording, prediction, rate-limit detection Refactoring | Strings, files, performance, idiom, async Config | Two objects — API + refactoring Auto-refactor | X2Y_AUTO_REFACTOR=true Licence | MIT Telemetry | 0 bytes — verified continuously Account required | None — ever Price | Free & open source Developer | x2y Devs Tools Ltd, Nairobi, Kenya Support ### Need help? For support and inquiries, contact the team directly. Bug reports and feature requests are welcome on GitHub — the SDK is MIT-licensed and contributions are encouraged. Email support support@x2ydevs.xyz GitHub issues x2yDevs/x2y-sdk Downloads ## Get x2y SDK v1.0.4 Free and open source. The x2y SDK is published under the MIT licence. Install from npm, clone from GitHub, or vendor the source directly into your project. No account, no key, no telemetry. npm x2y-dev-tools-sdk · PRIMARY GitHub SOURCE · MIT · ISSUES SDK docs sdk.x2ydevs.xyz Security model ## Your code and API data never leave your process Data policy. Telemetry: 0 bytes collected. Account required: none, ever. API traffic data: held in your process memory or written to paths you control. Source code analysed: read from paths you provide, never transmitted. Refactoring engine: runs locally, no cloud inference. Network connections: only the API calls your own application makes. Licence: MIT. The x2y SDK is a library that runs inside your application. It does not make any network calls of its own — the only traffic it observes is the traffic your code already generates. Recorded API metrics stay in your process memory unless you explicitly persist them. Source code passed to refactorCode or refactorFile is analysed in-process and never leaves your machine. There is no analytics endpoint, no crash reporter, no licence check, no cloud inference tier. Verify with Wireshark, mitmproxy or your firewall logs — you will observe zero outbound connections attributable to the SDK itself. Security manifest Telemetry | 0 bytes collected Account | None required — ever API traffic data | Your process memory or your filesystem Source analysis | In-process, never transmitted Refactoring engine | Local — no cloud inference Network | Only your application's own calls Licence | MIT — auditable source Verification | Any network monitor Architecture ## A library that observes your process instead of phoning home ### Nothing to call, nothing to leak The SDK runs inside your application and makes no network requests of its own. There is no analytics host, no licence ping, no crash reporter and no cloud inference tier in the bundle — which means the only traffic it can ever observe is traffic your code already generates. That constraint is the product. A hosted APM agent is a data-egress decision disguised as a dependency: your request bodies, headers and identifiers leave your process on a schedule set by someone else. Here, recorded metrics stay in memory or on paths you choose. ### Monitoring without a collector recordAPITraffic takes endpoint, method, timestamp, response time, status code and the headers you decide to capture. predictAPIIssues reads that local history for the shapes that precede failure: latency creeping toward a timeout, 429 responses approaching a limit, error-rate drift on a single route. Alerting thresholds are values in your config, not rules in a vendor's UI. The output is data your own logging, dashboards or on-call tooling can consume — which is why the package has no opinion about where the numbers ultimately go. ### Refactoring as an analysis pass, not a chat window refactorCode and refactorFile return suggestions for performance, idiom and async patterns: loops that should be map or forEach , sequential await calls that could run concurrently, missing rate-limit handling, callback shapes that want promises. It is static analysis of a syntax tree, executed in-process. Source never leaves your machine, and there is no model to send it to. Suggestions are advisory by design — you review and apply them; the SDK does not rewrite a file behind your back. ### Secrets and audit, from the same engines The secrets module exposes the local rule set that powers Code Leak Detector for scans of a working tree, and audit covers dependency integrity, licence compliance and supply-chain checks — including the question every install should ask, whether a package ships install scripts. That is the actual reason this SDK exists: the engines behind our desktop tools are useful in CI, so they ship as plain Node.js modules with first-class TypeScript types and no runtime requirement to talk to us. ### Supply chain, stated in numbers One package. Zero postinstall scripts. No native dependencies, so no build toolchain on the target and no prebuilt binary to trust. MIT licensed, so the source you install is the source you can read, fork and audit. Add npm audit , a lockfile and your own registry policy and the install path is as boring as a dependency should be. Boring is the goal: a monitoring library that itself needs monitoring is a bad trade. How it works ## Install, wrap, observe — no account to register #### Install and import npm install x2y-dev-tools-sdk . ES6 import and CommonJS require both work, and TypeScript definitions ship inside the package — no @types fetch, no separate release cadence to track. #### Wrap the boundary Wrap fetch or your HTTP client once. Every call that crosses that boundary becomes a record: endpoint, method, duration, status, and the headers you explicitly opted in to capture. #### Set thresholds locally Configure rate-limit headroom, prediction window and your API base URL in code or config. Values stay in your process; the behaviour of the module is fully determined by what you pass it. #### Act in your own pipeline Ask for predictions before a deploy, run refactoring suggestions in a lint step, scan for secrets before release and pipe the results into whatever reports, gates or dashboards you already run. Technical summary monitor | Traffic records, latency and status history, alert probes refactor | AST suggestions for performance, idiom and async patterns secrets | Offline rule pack, the same engine as Code Leak Detector audit | Dependency integrity, licence compliance, supply-chain checks types | TypeScript definitions bundled in the package runtime | Node.js 18 and above, including current LTS lines Confirm the claim in five minutes: run your app under mitmproxy , tshark or your own egress policy and observe zero outbound connections attributable to the SDK. A library that claims silence should be able to prove it, and this one is built so you can. Who it is for ## Where a local, embeddable engine beats a hosted agent ### Teams that cannot send payloads out Health, fintech, government and defence workloads where request bodies are protected data and an agent is a policy exception you have to renew. ### Performance and reliability work Latency drift and rate-limit headroom on your own endpoints, without standing up an APM stack for one service. ### CI pipelines and release gates Secret scanning plus dependency audit as fast, deterministic steps with exit codes and JSON output. ### Air-gapped and on-prem installs Software you ship to a customer's isolated network can include analysis that never needs a vendor endpoint. ### Code review automation Refactoring suggestions in a lint step — the advice is repeatable, because it is a syntax-tree pass and not a model call. ### Library authors and tooling teams A programmatic interface to the same engines our desktop apps use, with a documented API surface at sdk.x2ydevs.xyz . Requirements ## What the package expects from your environment x2y SDK runtime and toolchain requirements Requirement | Minimum | Notes Runtime | Node.js 18+ | Tested against current LTS lines; the README of the package states supported versions Package manager | npm | Works with yarn and pnpm through the same registry metadata Install scripts | None required | The package ships with zero postinstall scripts Native dependencies | None | No build toolchain or prebuilt binaries on the target Network at runtime | None | The modules never contact a vendor endpoint TypeScript | Optional | Type definitions are bundled in the package itself Licence | MIT | Use, fork and audit freely; the licence text ships with the source Module system | ES6 or CommonJS | Both entry points are supported from the same version Pin it like any dependency. Add the package to your lockfile, review the release diff, and treat version bumps as code review. MIT licensing means you can read the exact tag you install — and if a version matters to you, that reading takes minutes, not a support ticket. Context ## In-process SDK versus hosted APM versus hand-rolled logging Comparison of SDK monitoring, hosted APM and DIY logging Concern | x2y SDK | Hosted APM agent | Custom middleware logging Where data lands | Your process, your sinks | Vendor ingest and retention policies | Your logs, your format Setup | One import, no account | Agent, keys, dashboards, sampling config | Write and maintain it yourself Offline and air-gapped | Fully functional | Usually no | Fully functional Predictive analysis | Local thresholds over recorded history | Vendor models and alert rules | None, by definition Code-quality pass | Refactoring suggestions in the same package | Not in scope | Separate linters, separate config Cost model | MIT, free | Per-host or per-seat, always scaling | Engineering time Exit path | Delete a dependency | Export, renegotiate, rebuild dashboards | Nothing to leave Questions ## Evaluation notes from the people who file the issues Does the SDK send anything to x2y? No. It is a library that runs inside your application and makes no network calls of its own. Recorded metrics stay in process memory unless you explicitly persist them, and there is no analytics endpoint, crash reporter or licence check compiled into the package. Verify it under a network monitor if you would rather not take the claim on faith. Does it need an account, key or registry login? None. Install it from the public npm registry, import it, and it works. There is no free tier to hit, no seat count to report and no activation request to allow through your firewall. Which Node versions are supported? Node.js 18 and above. The package targets the LTS support matrix rather than pinning a single minor version, so an upgrade of your runtime does not require an upgrade of your analysis tooling. Is it ESM or CommonJS? Both. ES6 import and CommonJS require are supported from the same version, with the module and configuration examples on this page showing both styles. TypeScript definitions ship in the package, so there is no separate @types dependency to track. Can I use it in CI without sending code anywhere? Yes — that is the intended use. secrets and audit scan paths you provide and emit structured results; nothing is uploaded. Deterministic local analysis is precisely why these modules exist as a library rather than as a hosted scan. Will it slow down my requests? The monitoring path records values into in-memory structures; it performs no network I/O of its own and no cloud lookups. Cost is dominated by how much you choose to capture — record a status code and a duration rather than whole bodies and you will struggle to measure the difference. Does refactoring edit my files? No. Suggestions are returned for you to review and apply, whether interactively or in a lint step. Automatic rewriting of source you did not approve would be a very different tool. How is this different from running Gitleaks or a linter? It overlaps deliberately. The SDK bundles our own offline rule set — the same engine as Code Leak Detector — plus monitoring and refactoring in one dependency, with a single programmatic API and no separate binary to install on CI images. If you already run and love a dedicated tool, keep it; this is the version that fits inside a Node process. How do I get support or report a bug? Open an issue on the GitHub repository or email support@x2ydevs.xyz ; security disclosures go to security@x2ydevs.xyz and are triaged first. The full API reference lives at sdk.x2ydevs.xyz . Documentation ## References, source and the release record API reference Types, modules and examples npm package x2y-dev-tools-sdk · PRIMARY GitHub repository SOURCE · MIT · ISSUES SDK reference in docs Modules and quick start Security model Why egress is zero by design Changelog Suite-wide release history Read the specification section before you wire it up. Technical details on this page lists the module surface, runtime and licensing in one table, and Integration patterns shows the fetch-wrapper approach that keeps instrumentation to a single boundary. Ready to build ## Install x2y SDK — monitor APIs and refactor code in one import Free, MIT-licensed, zero telemetry. One npm install gives you predictive API monitoring and intelligent code refactoring — running entirely inside your own process. View on npm Clone from GitHub Summary Version | v1.0.4 Runtime | Node.js 18+ Licence | MIT — free & open source Telemetry | 0 bytes More from the suite ## Pairs well with ### Code Leak Detector v2.0.5 · WIN · $29 ONE-TIME ### x2y Devs Pad v2.0.0 · WIN · FREE ### SiteDirective v2.0.0 · WIN · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/extractor/ TITLE: x2y Extractor — Offline Archive Manager for Windows META DESCRIPTION: x2y Extractor is an offline Windows archive manager with AES-256 encryption, previews, 30+ formats, split and merge operations, and zero telemetry. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / x2y Extractor On this page Key features Supported formats Specifications Downloads Changelog Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Professional Archive Manager for Windows # x2y Extractor v2.1.0 Professional archive manager for Windows that lets you open, browse, extract, create, convert, split, and merge archive files entirely offline. Supports all major formats with full AES-256 password encryption. WINDOWS 10/11 AES-256 30+ FORMATS ZERO TELEMETRY Download free View on itch.io Free — no account, no cloud processing, no telemetry. Every operation runs entirely on your machine. At a glance - Version v2.1.0 - Platform Windows 10 / 11 - Read 30+ formats, incl. RAR - Write ZIP, 7Z, TAR, GZ, BZ2, XZ - Encryption AES-256 (ZIP, 7Z) - Price Free · donationware Download free Read the guide Dual-pane browser with inline previews and checksum verification before extraction. No cloud relay, ever. Key features ## Every archive operation, handled locally ### AES-256 encryption for ZIP and 7Z Create password-protected archives using industry-standard AES-256 encryption. Open encrypted archives with the same confidence — decryption happens entirely in memory on your device. No key material ever leaves your machine. ### Inline file previews Inspect archive contents before extracting anything. Preview text files, images, and metadata directly within the browser pane — no temporary extraction to disk, no leftover files. See exactly what is inside before you commit to unpacking. ### 30+ supported formats ZIP, 7Z, RAR (read-only), TAR, GZ, BZ2, XZ, ISO, CAB, WIM, MSI and more. Split archives (.001, .part1) are reassembled automatically. Convert between formats without leaving the application. ### Create, extract, split and merge Full lifecycle management for every archive type. Create new archives from files or folders, extract to any destination, split large archives into volume parts for transfer, and merge split volumes back into a single file. Supported formats ## Every major archive type, read and written locally All format handlers are bundled within the application. No codec downloads, no network fetches, no external dependencies. Highlighted formats support both reading and writing. ZIP 7Z RAR (read-only) TAR GZ BZ2 XZ ISO CAB WIM MSI Split (.001 / .part1) Specifications ## Technical details x2y Extractor specifications Product | x2y Extractor Version | v2.1.0 Platform | Windows 10, Windows 11 Read formats | ZIP, 7Z, RAR, TAR, GZ, BZ2, XZ, ISO, CAB, WIM, MSI, split volumes Write formats | ZIP, 7Z, TAR, GZ, BZ2, XZ, split volumes Encryption | AES-256 (ZIP, 7Z) Previews | Inline text, image and metadata preview Operations | Open, browse, extract, create, convert, split, merge Themes | Light and Dark Integrity | Checksum verification before extraction Processing | 100% local — no cloud relay Telemetry | 0 bytes — verified continuously Account required | None — ever Price | Free Developer | x2y Devs Tools Ltd, Nairobi, Kenya Quick start ### From install to first extraction in four steps - 01 #### Install Download from Microsoft Store or itch.io. Run the installer — no administrator privileges required for standard installs. No account creation, no activation key. - 02 #### Open an archive Double-click any supported archive in Explorer, or drag it into the x2y Extractor window. The file browser loads the archive contents instantly — no full extraction required to browse. - 03 #### Preview and verify Click any file to preview its contents inline. Check the archive properties panel for compression ratio, file count and integrity status. Confirm everything looks correct before extracting. - 04 #### Extract, create or convert Extract selected files or the entire archive to any destination. Create new archives with optional AES-256 encryption. Convert between formats or split large archives into manageable volumes. Encrypted archives. When opening a password-protected ZIP or 7Z file, the decryption key is held only in memory for the duration of the session. It is never written to disk, never cached, and never transmitted. Close the archive and the key is gone. Downloads ## Get x2y Extractor v2.1.0 Verify before installing. Every release is signed. Compare the published checksum on the release page against your downloaded file before running the installer. Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Changelog ## Release history 2026 v2.1.0 AES-256 encryption support for ZIP and 7Z archive creation and opening. Inline file previews for text, images and metadata within the browser pane. Dark theme added alongside the existing light theme. Archive properties panel with compression ratio, file count and integrity status. Improved split archive handling for .001 and .part1 volumes. 2025 v2.0.0 Interface rewrite with dual-pane file browser. Expanded format support to 30+ types including ISO, CAB, WIM and MSI. Format conversion between archive types. Batch extraction with destination presets. 2025 v1.x Initial release. Core extraction engine for ZIP, 7Z, RAR (read-only), TAR, GZ and BZ2. Basic create and extract operations. Security model ## Your files are unpacked on your machine, nowhere else Data policy. Telemetry: 0 bytes collected. Account required: none, ever. File access: only archives you explicitly open. Decryption keys: held in memory only, never written to disk. Cloud processing: none — every operation runs on your hardware. Licence: free. x2y Extractor reads the archives you open, performs the operations you request, and writes the results to the destination you choose. It does nothing else. There is no analytics SDK, no crash reporter, no licence verification call, no cloud decompression service, no "help improve" telemetry pipeline. Encrypted archive keys exist only in volatile memory for the duration of the session and are discarded the moment the archive is closed. Verify with Wireshark, Fiddler, GlassWire or your firewall logs — you will observe zero outbound connections. Security manifest Telemetry | 0 bytes collected Account | None required — ever File access | Only archives you explicitly open Decryption keys | Memory only — never written to disk Cloud processing | None — all operations local Network | Zero outbound connections Verification | Any network monitor Working with archives ## The unglamorous details that decide whether an archive tool is trustworthy ### Read broadly, write deliberately Extraction accepts ZIP, 7Z, RAR, TAR, GZ, BZ2, XZ, ISO, CAB, WIM and MSI, plus split volumes in .001 and .part1 form. Creation writes ZIP, 7Z, TAR, GZ, BZ2 and XZ, including split output for media that must fit a size limit. RAR is read-only because the proprietary compression format's write licence is not something a free tool can carry honestly. Rather than ship a shaky reimplementation, we open what people send you and create in the two formats that matter — ZIP for compatibility, 7Z for ratio and AES-256. ### AES-256, and what a password does not do Encrypted ZIP and 7Z archives use AES-256, and file names are protected in 7Z headers, which ZIP cannot fully do. That difference is the reason to prefer 7Z when the contents are sensitive and the receiving tool supports it. The rest is up to the passphrase: an archive is a long-lived file, and one you may hand to someone else or upload somewhere public. A short dictionary password is brute-forced offline by anyone holding the file, so length beats symbol soup. Encrypting also does not anonymise contents when metadata leaks — check the preview pane before you send. ### Verify before you extract Extracting blindly is how a corrupt archive becomes a half-written tree. x2y Extractor surfaces integrity status and checksum verification in the archive properties panel, alongside compression ratio and file count, so the archive is judged before it is unpacked. That habit generalises. Archives from untrusted sources deserve a look inside first: browse the paths in the preview, note executable and script entries, and extract into a dedicated folder rather than your documents tree. ### Previews and the dual-pane habit Inline previews for text, images and metadata mean the common question — is this the right build? does this contain the config I need? — gets answered without extracting 4 GB to find out. The dual-pane browser keeps source and destination visible at once, which is what actually prevents extraction into the wrong folder. Batch extraction with destination presets covers the repetitive case: a folder of per-customer archives that all follow the same layout. Light and dark themes are a preference, not a subscription tier. How it works ## Open, inspect, then extract or convert #### Open an archive Double-click, drag into the dual-pane browser, or use Open With . Contents list without extraction, including entries inside split volumes. #### Preview and verify Check integrity status, file count, compression ratio and inline previews. Confirm the tree looks like what you expect before anything is written to disk. #### Extract, create or convert Extract to a chosen destination, create a new ZIP or 7Z with AES-256 and a passphrase, convert between supported formats, or split output for a size target. #### Merge and check Rejoin split volumes for oversized transfers, then verify the merged archive's integrity before treating it as final. Technical summary Extraction | Single files, trees and batch with presets Creation | ZIP, 7Z, TAR, GZ, BZ2, XZ Split and merge | .001 and .part1 volumes Encryption | AES-256 for ZIP and 7Z creation and opening Integrity | Checksum verification plus archive properties Interface | Dual-pane browser, inline previews, light and dark On offline handling: nothing in x2y Extractor contacts a service — no file-type telemetry, no 'repair in the cloud', no analytics on the names of what you open. The processing model is identical to the rest of the suite: local, verifiable, 0 bytes out. Who it is for ## Archive work that a shell command or Explorer struggles with Six jobs where a local archiver beats a shell one-liner, a cloud upload or four separate utilities ### Developers shipping build artefacts Create a split, encrypted 7Z for a large release, then verify the volumes merge back into an identical tree. ### Sensitive handovers AES-256 with a passphrase sent out of band — for credentials, client data and exports that must not sit unencrypted in transit or in storage. ### IT and support Open whatever a user sends — ISO, CAB, WIM, MSI, RAR — without installing a suite per format or asking them to re-zip it. ### Researchers and curators Browse inside archives and preview contents instead of unpacking gigabytes to find one document. ### Media and design teams Split volumes for size-capped transfers and mailboxes, merged on arrival with integrity confirmed. ### Anyone tidying a downloads folder Inspect and extract odd formats in one tool, with the same behaviour on every Windows 10 or 11 machine you touch. Prerequisites ## Formats, capabilities and limits, stated plainly x2y Extractor format and capability matrix Requirement | Supported | Notes Read formats | ZIP, 7Z, RAR, TAR, GZ, BZ2, XZ, ISO, CAB, WIM, MSI, split volumes | RAR is read-only by design Write formats | ZIP, 7Z, TAR, GZ, BZ2, XZ, split volumes | Prefer 7Z for ratio and header protection Encryption | AES-256 for ZIP and 7Z | 7Z also protects file names in the header Operating system | Windows 10 or Windows 11 | No shell extensions required to open files Privileges | Standard user account | Extraction needs write access to the destination only Network | None | Used only to download the installer Previews | Text, images and metadata | Answering 'is this the right archive' without extracting Format support is the roadmap. New read formats are added when a free, auditable implementation exists; write support is limited to formats whose encryption we can state accurately. If a format you depend on is missing, say so at support@x2ydevs.xyz . Context ## Local archive manager versus cloud and shell workflows Comparison of local, cloud and command-line archive handling Concern | x2y Extractor | Cloud file service | Command-line 7-Zip or tar Where contents sit | On your disk only | Uploaded, synced, retained per provider policy | Local Encryption on share | AES-256 archive with your passphrase | Provider-managed keys, link permissions | Password support, awkward syntax Browse before extract | Inline previews and properties | Varies by client | Usually extract first Rare formats | ISO, CAB, WIM, MSI, RAR read | Whatever the server converts | Depends on what you installed Learning curve | GUI, dual-pane, drag and drop | Low | Flags per format and compression level Telemetry | 0 bytes | Product analytics | None Cost | Free · donationware | Subscription for capacity and retention | Free Questions ## Before you replace your current archiver Can I create RAR archives with it? No. RAR's proprietary compression format is read-only here; we open what people send you and create in ZIP or 7Z. If a recipient genuinely needs RAR, create a 7Z and confirm their tooling — the ratio and AES-256 support are usually better, not worse. Is extracting an untrusted archive safe? Safer if you inspect first, which is why the preview pane and integrity status exist. Browse paths, watch for executable and script entries, and extract into a dedicated folder rather than your documents tree. No archive tool can make a malicious payload harmless; this one at least lets you look before you unpack. Which should I use for an encrypted archive — ZIP or 7Z? 7Z, when the receiving side supports it. Both use AES-256, but 7Z additionally protects file names in the header, so the structure of what you are sending is not visible without the passphrase. Can it repair a broken archive? It reports integrity status so you know whether an archive is damaged, and it merges split volumes back together. Full recovery of a corrupt archive is a different problem, and we would rather tell you that than pretend. Does opening an archive upload anything? Nothing. Processing is entirely local — there is no cloud relay, no file-name telemetry and no analytics hook. Verification is the same as the rest of the suite: watch the machine under any network monitor. Is it free for business use? Yes. x2y Extractor is free for personal and commercial use under the donationware model adopted in July 2026, with no seats to count and no key to keep. Contributions are optional; see Support the project . How do I get an archive into the tool quickly? Double-click an associated file, drag it into the dual-pane browser, or right-click and use Windows Open With . Batch extraction with destination presets covers a folder of archives that share a structure. Documentation ## Guides, formats and downloads Extractor reference Formats, encryption, operations Installation guide Windows install and verification Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Release history What changed in v2.1.0 Support the project Keep the suite free Archive hygiene is a security control. Compressing credentials or exports before they leave the machine is exactly the workflow Code Leak Detector scans for — pair the two before you attach anything to a ticket or a mail. Ready to unpack ## Download x2y Extractor — open, encrypt, and convert, entirely offline No account. No telemetry. No cloud. Just a fast, capable archive manager that handles every format you throw at it — with AES-256 when the contents demand it. Get from Microsoft Store Download on itch.io Summary Version | v2.1.0 Platform | Windows 10 / 11 Price | Free Telemetry | 0 bytes More from the suite ## Pairs well with ### x2y Devs Pad v2.0.0 · WIN · FREE ### Code Leak Detector v2.0.5 · WIN · $29 ONE-TIME ### GitIgnore Generator v1.0 · WIN · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/devs-pad/ TITLE: x2y Devs Pad — Offline Code & Text Editor for Windows META DESCRIPTION: x2y Devs Pad is an offline Windows text and code editor with CLI support, 30+ syntax languages, tabbed editing, auto-save, backups and zero telemetry. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / x2y Devs Pad On this page Core features Editing features Specifications Downloads Changelog Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Professional Text Editor for Developers # x2y Devs Pad v2.0.0 A professional text editor combining the simplicity of Windows Notepad with powerful tools for coding, scripting, and managing text files. Supports command-line usage, file associations, syntax highlighting for 30+ languages, and advanced editing features. WINDOWS 30+ LANGUAGES CLI SUPPORT ZERO TELEMETRY Download free View on itch.io Free — no account, no subscription, no telemetry. A fast, quiet editor that respects your machine. At a glance - Version v2.0.0 - Platform Windows · x64 - Highlighting 30+ languages - CLI x2ydevspad + file:line - Price Free · donationware - Telemetry 0 bytes Download free Read the guide Notepad's reflexes, an editor's tooling: no extensions marketplace, no background indexer, no sign-in. Core features ## Notepad simplicity, developer power ### Command Line Support Launch from any terminal with x2ydevspad filename.txt . Pipe output directly into the editor, open multiple files at once, or integrate into build scripts and automation workflows. The CLI is a first-class citizen, not an afterthought. ### File Association and Open With integration Register x2y Devs Pad as the default handler for any file extension. Right-click any file in Explorer and choose "Open with x2y Devs Pad". Seamless integration with the Windows shell — no context menu hacks, no registry tweaks. ### Line Number Navigation Jump directly to any line from the command line: x2ydevspad script.py:42 opens the file and places the cursor on line 42. Use Go to Line (Ctrl+G) inside the editor for instant navigation within large files. ### Auto-Save with Backup System Never lose work to a crash or power failure. Auto-save writes changes at configurable intervals, and the backup system retains the last 5 versions of every file. Roll back to any previous state with a single click. Editing features ## Everything you need between the keyboard and the file ### Syntax Highlighting (30+ languages) Automatic language detection by file extension with manual override. Highlighting covers JavaScript, TypeScript, Python, C, C++, C#, Java, Rust, Go, Ruby, PHP, HTML, CSS, SQL, Shell, YAML, JSON, XML, Markdown and more — all rendered locally with zero external dependencies. ### Find and Replace with history Full regex support in both find and replace fields. Search history persists across sessions so your most-used patterns are always one keystroke away. Case-sensitive, whole-word and selection-scoped search modes. ### Go to Line, Zoom In/Out Ctrl+G jumps to any line number instantly. Ctrl+Plus and Ctrl+Minus adjust the editor font size on the fly — useful for presentations, pair programming or tired eyes. Zoom level persists per session. ### Word Wrap toggle, Line Numbers Toggle word wrap on or off with a single shortcut — no settings dialog required. Line numbers display in the gutter with current-line highlighting. Both features are independently configurable and remembered per file type. Specifications ## Technical details x2y Devs Pad specifications Product | x2y Devs Pad Version | v2.0.0 Platform | Windows CLI binary | x2ydevspad Line navigation | x2ydevspad file.py:42 Syntax languages | 30+ (auto-detect + manual override) Auto-save | Configurable interval Backup retention | Last 5 versions per file Find & Replace | Regex, case-sensitive, whole-word, selection scope Search history | Persists across sessions Navigation | Go to Line (Ctrl+G), Zoom In/Out Display | Word wrap toggle, line numbers, current-line highlight File associations | Windows shell integration, Open With Telemetry | 0 bytes — verified continuously Account required | None — ever Price | Free Developer | x2y Devs Tools Ltd, Nairobi, Kenya Quick start ### From install to first edit in four steps - 01 #### Install Download from Microsoft Store, itch.io or Uptodown. Run the installer — no administrator privileges required for standard installs. No account creation, no activation key. - 02 #### Set file associations Right-click any text file, choose "Open with", and select x2y Devs Pad. Or register it as the default for specific extensions from the settings panel. The editor integrates with the Windows shell natively. - 03 #### Edit from anywhere Double-click a file in Explorer, or open a terminal and run x2ydevspad config.yaml . Jump to a specific line with x2ydevspad app.js:128 . Pipe output: dir /b | x2ydevspad . - 04 #### Trust the backup Auto-save runs silently in the background. If something goes wrong, open the backup panel and restore any of the last 5 saved versions. Your work is never more than a few seconds old. Terminal x2ydevspad notes.md x2ydevspad src/app.ts:42 git diff | x2ydevspad # All commands open instantly — no splash screen, no loading spinner Downloads ## Get x2y Devs Pad v2.0.0 Verify before installing. Every release is signed. Compare the published checksum on the release page against your downloaded file before running the installer. Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Uptodown WINDOWS MIRROR Changelog ## Release history 2026 v2.0.0 Major update. CLI companion binary ( x2ydevspad ) with line-number navigation and pipe support. UI refinements across the editor chrome. Syntax highlighting expanded to 30+ languages. Auto-save with 5-version backup retention. Find and Replace with regex and persistent search history. File association and Windows shell integration. Go to Line (Ctrl+G), Zoom In/Out, word wrap toggle and line numbers. 2025 v1.x Initial release. Core text editing engine with basic syntax highlighting. Manual save only. No CLI support. Security model ## A text editor should read files, not phone home Data policy. Telemetry: 0 bytes collected. Account required: none, ever. File access: only files you explicitly open. Auto-save and backups: written to local filesystem only. Network connections: none — the editor makes zero outbound connections under any circumstance. Licence: free. x2y Devs Pad is a text editor. It reads the files you tell it to read, writes the changes you make, and does nothing else. There is no analytics SDK, no crash reporter, no licence verification call, no "help improve" telemetry pipeline, no cloud sync, no account system. The auto-save and backup files are written to your local filesystem and exist nowhere else. Verify with Wireshark, Fiddler, GlassWire or your firewall logs — you will observe zero outbound connections. Security manifest Telemetry | 0 bytes collected Account | None required — ever File access | Only files you explicitly open Auto-save | Local filesystem only Backups | Local filesystem only (last 5 versions) Network | Zero outbound connections Verification | Any network monitor Editor philosophy ## Small on purpose: what a reflexes-first editor is for ### The gap between Notepad and an IDE Notepad opens instantly and does almost nothing. A full IDE indexes your workspace, wants a project, and costs seconds before you can read one file. Most real editing is not project work: it is checking a config value, trimming a CSV column, fixing one line in a script, reading a log excerpt with line numbers on. x2y Devs Pad targets that gap. Auto-save with five retained backup versions per file means the quick-edit scenario cannot silently destroy anything; syntax highlighting for 30+ languages means the same file stays readable; and the CLI means the editor is reachable from the place you already are. ### Why the CLI belongs in a text editor x2ydevspad script.py:42 opens the file and jumps straight to line 42 — the exact behaviour a compiler or linter message wants to hand you. Combined with Open With and Windows shell file associations, the editor slots into terminal-first and double-click workflows without a project or a workspace file. There is no daemon, no extension host and no indexer to wait for. Open, edit, save: the same model as Notepad, with the tools that make repeated edits safe. ### Auto-save with a real retention policy Auto-save on its own is a data-loss mechanism dressed as a convenience. Devs Pad keeps the last five versions of each file, so the interval is a safety net rather than a gamble. That choice reflects the intended use: quick, frequent edits where a mis-keyed save should be recoverable without a manual versioning habit. ### Search you can rely on, offline Find and Replace supports regex, case sensitivity, whole-word matching and a scope limited to the current selection, with search history persisted across sessions. Go to Line sits on Ctrl+G; word wrap, line numbers and current-line highlighting are toggles rather than settings buried in a menu. None of it needs a network, an account or a language server. Everything the editor knows about your files stays on the disk they were opened from. How it works ## Shell integration in four steps #### Install and associate Run the signed installer from Microsoft Store, itch.io or Uptodown. Choose the extensions you want Devs Pad to handle; no account and no first-run survey. #### Open from anywhere Double-click a file, use Windows Open With , or call x2ydevspad notes.md from a terminal. Add :line to land on the exact row a tool reported. #### Edit with the safety net Auto-save keeps the file current and rotates the last five versions. Regex find and replace with selection scope handles the bulk-and-boring edits. #### Verify and ship Confirm the change on disk, then move on. There is nothing to sign in to, nothing indexing in the background and nothing phoning home to check. Technical summary CLI binary | x2ydevspad with file:line navigation Shell integration | File associations and Open With Highlighting | 30+ languages, auto-detect plus manual override Backups | Last 5 versions retained per file Search | Regex, case, whole-word, selection scope Navigation | Go to Line (Ctrl+G), Zoom In/Out, word wrap A note on scope. Devs Pad has no extension marketplace, no integrated terminal and no debugger — by choice. It is the editor you keep installed for the 30 edits a day that do not deserve an IDE, and the reference documents exactly which features it does and does not attempt. Who it is for ## The editors people actually keep pinned Six jobs a small, fast editor handles better than a workspace. ### Terminal-first developers Open the exact file and line a build error reported, save, and close — without waiting on an indexer. ### Writers and note-takers Plain files, no format lock-in, no cloud document to migrate away from, and highlighting when you paste code. ### Ops and support staff Read a config, change one value, confirm the diff in your own tooling. Auto-save backups cover the mistake you did not mean to make. ### Data spot-checks Line numbers, word wrap and find-with-history make a 40,000-row CSV inspection survivable. ### Editors of other people's machines Runs from a user folder on a shared or locked-down workstation, with no account to sign in to. ### Anyone migrating off Notepad The same reflexes and shortcuts, plus syntax colour, regex search and versioned saves. Prerequisites ## What Devs Pad needs — which is very little x2y Devs Pad prerequisites Requirement | Minimum | Recommended Operating system | Windows 10 | Windows 11 Privileges | Standard install needs no administrator rights | Portable use from a user folder on shared machines Network | None — the editor is fully offline | A connection only to download the installer Disk | Space for the installed editor | Room for five retained backup versions per file you edit often Shell integration | Optional file associations | Associate only the extensions you actually edit CLI access | x2ydevspad filename | Add it to your PATH so tools can hand files to the editor Verification | Published SHA-256 checksum on the release page | Compare with PowerShell Get-FileHash before installing Nothing to sign in to. No account, no licence key, no cloud settings sync. Your file associations live in Windows; your backups live next to your files; and the only network traffic this editor generates is the download of the installer itself. Context ## Devs Pad against the two editors it sits between Pick the tool that matches the edit, not the marketing page. Comparison of lightweight, default and full editors Property | x2y Devs Pad | Windows Notepad | Full IDE or Electron editor Cold start | Instant | Instant | Workspace and indexer first Syntax highlighting | 30+ languages | None or minimal | Full language services Go to a specific line | file:42 from the CLI | Line numbers only, no CLI | Supported Versioned backups | Last 5 versions per file | None | Depends on your VCS Regex find and replace | Built in | Basic or absent | Built in Extensions and LSP | Deliberately absent | Not applicable | The main reason to use it Telemetry | 0 bytes | Per OS settings | Varies by product and settings Cost | Free · donationware | Included with Windows | Free to several hundred dollars a year Questions ## Is this the right editor for you? Is x2y Devs Pad a VS Code replacement? No, and it would be dishonest to claim otherwise. There is no extension marketplace, no debugger, no language server protocol client and no integrated terminal. It is the editor you reach for to read, tweak and save a file — while a full IDE stays the right tool for project-scale work. Can I open a file at a specific line from the command line? Yes: x2ydevspad script.py:42 opens the file with the caret on line 42. That is the intended integration point for compilers, linters and test runners that report locations as file:line . What happens to my file if auto-save catches a mistake? Auto-save rotates the last five versions of each file, so an unwanted save is recoverable by rolling back. Set the interval to suit the file: aggressive for scratch work, longer for anything you hand-edit carefully. Does it index or upload my files? Neither. There is no background indexer and no account to sync to. Devs Pad reads and writes the paths you open, and nothing else — verified continuously at 0 bytes of telemetry, like every tool in the suite. Will it handle a large log or CSV? It is built for reading and quick edits with line numbers, word-wrap toggles and search with history. For analysis — filtering, aggregating, pivoting — use a real data tool; for opening a large text file to find and fix something, that is what this is for. Which languages get highlighted? 30-plus, auto-detected by file type with a manual override. The current list is in the product reference ; if your language is missing, tell us via support@x2ydevs.xyz . Is it free for commercial use? Yes. Since July 2026 the whole suite except Code Leak Detector is free for personal and commercial use as donationware, with no seat counts to track and no licence key to store. Documentation ## Guides, CLI notes and the release record Devs Pad reference Features, CLI and shortcuts Installation guide Windows install and checksums Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Uptodown mirror WINDOWS MIRROR Code Leak Detector Scan what you just saved Pair it with the rest of the local workflow. Editing is only one step: GitIgnore Generator keeps secrets out of the commit, and Extractor handles the archives your edits ship inside. Ready to edit ## Download x2y Devs Pad — fast, quiet, and entirely yours No account. No telemetry. No cloud. Just a text editor that opens instantly, highlights your code, saves your work and gets out of your way. Get from Microsoft Store Download on itch.io Summary Version | v2.0.0 Platform | Windows Price | Free Telemetry | 0 bytes More from the suite ## Pairs well with ### GitIgnore Generator v1.0 · WIN · FREE ### Code Leak Detector v2.0.5 · WIN · $29 ONE-TIME ### x2y Extractor v2.1.0 · WIN · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/products/gitignore-generator/ TITLE: x2y GitIgnore Generator — Offline Repository Scanner META DESCRIPTION: x2y GitIgnore Generator creates project-aware .gitignore files from 20+ templates and scans repositories for dangerous exposures, entirely offline on Windows. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Products / x2y GitIgnore Generator On this page Key features Supported templates Specifications Downloads Changelog Security model Under the hood How it works Use cases Requirements Compare FAQ Resources Never Commit Secrets Again # x2y GitIgnore Generator v1.0.0 The essential security companion for modern developers. Whether you are working in Python, Node.js, React, or C++, ensuring your sensitive data stays out of your public repositories is critical. Generate the perfect .gitignore file in seconds and audit existing projects for dangerous exposures. WINDOWS 20+ TEMPLATES REPO SCANNING ZERO TELEMETRY Download free View on itch.io Free — no account, no cloud lookup, no telemetry. Templates ship with the app and work entirely offline. At a glance - Version v1.0.0 - Platform Windows - Templates 20+ bundled offline - Audit Unignored-file scanning - Output Clipboard or atomic write - Price Free Download free Read the guide Templates are bundled locally and never fetched over the network — so it works on a plane, in a lab or on a fresh machine. Key features ## Stop the "Oops, I committed my .env" nightmare ### Generate the perfect .gitignore in seconds Select your stack from curated templates, preview the merged output in real time, and write directly to your repository root. The generator combines rules intelligently — no duplicates, no conflicts, no manual editing required. ### Audit existing projects for dangerous exposures Point the scanner at any repository and it identifies files that should be ignored but are not — .env files, API keys, credentials, build artifacts, OS metadata and editor swap files. Catch the exposure before it reaches a remote. ### Save custom templates for reuse Build your own template combinations and save them for future projects. Export and import templates as portable files so your team shares the same ignore standards across every repository. ### Copy to clipboard or save directly Generate the output and copy it to your clipboard with one click, or write it atomically to the target directory. The diff preview shows exactly what will change before anything is written — no surprises. Supported templates ## 20+ curated templates covering every major stack Each template is maintained and updated locally within the application. No network fetch is required — the full template library ships with the installer and works in air-gapped environments. Node.js Python React Vue Angular PHP Ruby Rust C++ C# Java Go Swift Kotlin macOS Windows Linux VSCode Vim IntelliJ Sublime Text Unity Unreal Engine Specifications ## Technical details x2y GitIgnore Generator specifications Product | x2y GitIgnore Generator Version | v1.0.0 Platform | Windows Templates | 20+ curated (languages, frameworks, editors, OS) Template storage | Bundled locally — no network fetch Repository scanning | Detects unignored sensitive files Audit targets | .env, API keys, credentials, build artifacts, OS metadata, editor swaps Custom templates | Create, save, export, import Output | Copy to clipboard or atomic file write Diff preview | Shows changes before writing Merge logic | Deduplication and conflict resolution Telemetry | 0 bytes — verified continuously Account required | None — ever Price | Free Developer | x2y Devs Tools Ltd, Nairobi, Kenya Quick start ### From install to protected repo in four steps - 01 #### Install Download from Microsoft Store, itch.io or Uptodown. Run the installer — no administrator privileges required for standard installs. No account creation, no activation key. - 02 #### Select your stack Open the Generate tab and check the templates that match your project — Node.js + VSCode + macOS, for example. The preview pane updates in real time as you toggle templates. - 03 #### Audit an existing repo Switch to the Audit tab and point it at a repository. The scanner identifies files that should be ignored but are not — .env files, credential stores, build outputs — and flags them by severity. - 04 #### Write or copy Review the diff preview, then write atomically to the repository root or copy the output to your clipboard. Save the template combination for reuse on future projects. Already committed a secret? Adding a .gitignore rule does not remove a file from Git history. If a secret was already pushed, rotate the credential immediately and use git filter-repo or BFG Repo-Cleaner to purge it from history. The Code Leak Detector can help identify what was exposed. Downloads ## Get x2y GitIgnore Generator v1.0.0 Verify before installing. Every release is signed. Compare the published checksum on the release page against your downloaded file before running the installer. Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Uptodown WINDOWS MIRROR Changelog ## Release history 2026 v1.0.0 Initial release. 20+ curated templates covering Node.js, Python, React, Vue, Angular, PHP, Ruby, Rust, C++, C#, Java, Go, Swift, Kotlin, macOS, Windows, Linux, VSCode, Vim, IntelliJ, Sublime Text, Unity and Unreal Engine. Repository scanning for unignored sensitive files (.env, API keys, credentials, build artifacts, OS metadata, editor swaps). Custom template creation, save, export and import. Real-time merge preview with deduplication. Atomic file write with diff preview. Copy-to-clipboard output. Built-in help guide. 100% offline — all templates bundled locally. Security model ## Your repository structure is nobody else's business Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Repository scanning: reads only the directories you explicitly select. Template library: bundled locally, never fetched from a server. Network connections: none — the application makes zero outbound connections under any circumstance. Licence: free. x2y GitIgnore Generator reads the file tree of the repository you point it at — that is its function. It does not transmit the file list, the generated .gitignore content, or any other data anywhere. The template library is embedded in the installer and exists entirely on your filesystem. There is no analytics SDK, no crash reporter, no licence verification call, no cloud sync. Verify with Wireshark, Fiddler, GlassWire or your firewall logs — you will observe zero outbound connections. Security manifest Telemetry | 0 bytes collected Account | None required — ever Repo scanning | Only directories you explicitly select Template library | Bundled locally, never fetched Generated output | Never transmitted Network | Zero outbound connections Verification | Any network monitor Why this file matters ## A .gitignore is the cheapest security control in a repository ### The failure mode is asymmetric A missing entry costs nothing on Monday and everything on the day you open-source the repository. .env files, key pairs, database dumps and IDE swap files look like harmless local clutter right up until they are indexed by a search engine and swept by credential crawlers. Ignoring files is not a formatting preference; it is the first line of defence for secrets. That is why this generator treats an existing repository as a first-class input, not an afterthought: generate the file, then audit what is already tracked. ### Stacking templates is where mistakes hide Real projects are a stack: Node plus React plus VS Code plus macOS, or Python plus Django plus PostgreSQL. Choosing one template is how half the gaps appear. The generator lets you select several, merges them with deduplication and conflict resolution, and shows a diff preview before it writes — so you can see what changed instead of trusting a paste. All 20-plus templates ship inside the app. Nothing is fetched from a gist or a repository at runtime, which means the output is reproducible and works with the network cable out. ### Auditing an existing project The scanner walks a repository for the exposures that survive a good intention: unignored .env files, API keys and credential material, build artefacts, OS metadata like .DS_Store and editor swap files. It reports what should be ignored and, importantly, what is already tracked. Tracked files are the trap. Removing a path from tracking with git rm --cached stops future commits from including it; it does not erase it from history, and it does not make a committed credential safe. Rotate the credential, then decide how much history you must actually rewrite. ### Custom templates, kept local Your stack is probably not in any public list: the internal SDK folder, the licence file that must never ship, the generated client directory. Create a custom template, save it, export it to a colleague, import it on the next machine. It stays on disk as a plain file you can diff and version. Atomic writes and a copy-to-clipboard output cover both habits: let the tool write the file with a previewed diff, or take the text and paste it into your own commit. How it works ## Generate for a new repo, audit an old one #### Select your stack Tick the languages, frameworks, editors and operating systems in play. The merge step deduplicates and resolves conflicting rules. #### Preview the diff For a new file, read what will be written. For an existing .gitignore , the diff shows exactly which lines are added or changed before anything touches disk. #### Audit the working tree Run repository scanning to find unignored sensitive files and build artefacts that survived a previous ignore — including files already tracked. #### Write or copy Atomic file write or clipboard copy, your choice. Save the combination as a custom template for the next project in the same stack. Technical summary Template scope | Languages, frameworks, editors, OS, IDEs Merge behaviour | Deduplication with conflict resolution Audit targets | .env , keys, credentials, artefacts, OS and editor noise Write mode | Atomic write with diff preview, or clipboard Custom rules | Create, save, export, import as plain text Offline | Every template bundled in the app Ignore files, then verify the ignore worked. After writing the file, run git status --ignored in the repository to confirm your sensitive paths are listed as ignored. If a file was already tracked, git rm --cached it and rotate any credential it contained. Who it is for ## Every repository you expect to outlive your own attention ### Open-source authors The moment a private repository turns public is the moment every tracked secret is collected. Generate and audit before you flip the switch. ### Agencies and consultants One custom template per client stack, exported and versioned, so the next project starts from your standard rather than a stranger's gist. ### Teams shipping mobile and game builds Unity and Unreal directories, keystores and provisioning profiles are exactly the artefacts that must never be committed. ### Security reviewers A fast, offline check for exposure before a repository is shared, published or handed over. ### Students and side projects The habit costs a minute now and prevents the most common first-repository mistake there is. ### Anyone cleaning up an old repo Existing repositories are where the surprises are. The audit reads the tree you inherited and tells you what to fix first. Prerequisites ## What the tool needs and what it will not do x2y GitIgnore Generator prerequisites Requirement | Details | Notes Operating system | Windows 10 or Windows 11 | No .NET or runtime prerequisite to install separately Repository | A folder containing your project | Git does not need to be initialised to generate the file Privileges | Standard user account | Writes only where you have file permissions Network | None | Templates are bundled; nothing is fetched at runtime Existing .gitignore | Read, diffed, merged | Never overwritten silently — the diff preview shows the change History rewriting | Out of scope, deliberately | Rotate credentials first; history surgery is a git operation Verification | Published SHA-256 checksum per release | Compare with PowerShell Get-FileHash before installing Scope, honestly stated. This tool writes ignore rules and audits a working tree. It does not rewrite Git history, does not manage secrets and does not replace a secret scanner — those are three different jobs, and the suite covers all three. Context ## Desktop generator versus copy-pasting a template Comparison of generated, pasted and manual ignore files Concern | x2y GitIgnore Generator | Online template collections | Hand-written .gitignore Multi-stack merge | Deduplicates and resolves conflicts | Manual concatenation, duplicates and gaps | Whatever you remembered Audit of tracked files | Built in | None | None Works offline | Fully | Needs a browser and a fetch | Yes Diff preview before write | Yes, atomic write | Copy-paste and hope | You are the diff Reusing your own stack | Custom templates, export and import | Your bookmarks folder | Your project templates Cost | Free | Free, usually with ads | Your time Questions ## Ignore files, secrets and history Is this better than copying a template from GitHub? Different in two ways. First, you can stack several templates and the tool merges them with deduplication and conflict resolution, which is where pasted collections usually fail. Second, the audit looks at the repository you already have. Downloading a good template never told you that .env was already committed. Does it rewrite Git history if a secret was committed? No. Nothing in this tool rewrites history, and it should not be the first thing you reach for: rotate the credential immediately, then decide whether history needs surgery. git rm --cached stops future tracking; it does not remove the past. Will it delete or modify my files? No. It writes or copies the .gitignore text and reports findings. The audit is read-only, and any write goes through a diff preview with an atomic file write, so you always see the exact change first. Does it scan node_modules ? Scanning focuses on the exposures that matter: unignored .env files, key material, credential files, build artefacts, OS metadata and editor swaps. Ignored directories are not interesting — the question is always what is not ignored. Which stacks are covered? 20-plus curated templates spanning Node.js, Python, React, Vue, Angular, PHP, Ruby, Rust, C++, C#, Java, Go, Swift, Kotlin, macOS, Windows, Linux, VSCode, Vim, IntelliJ, Sublime Text, Unity and Unreal Engine — all bundled in the app, so generation works offline. Can I use it on a monorepo? Yes. Generate a root file from the union of the stacks in play, then save that combination as a custom template. Package-level .gitignore files still follow the usual Git rule that ignore patterns are evaluated per directory. Why not just a CLI script? If a script already fits your workflow, keep using it. The desktop app exists for the other 90 per cent of cases: opening an inherited project, previewing a merge, auditing without cloning into a terminal, and doing it all on a machine with no network access. Is it free for commercial use? Yes — donationware, like the rest of the suite apart from Code Leak Detector. No seats, no keys, no account. Optional contributions are what keep signing certificates and build infrastructure paid for: Support the project . Documentation ## Guides, templates and next steps Generator reference Templates and audit workflow Installation guide Windows install and verification Microsoft Store PRIMARY · AUTO-UPDATES itch.io FREE · INSTALLER Uptodown mirror WINDOWS MIRROR Code Leak Detector Deep-scan what got committed The pair that closes the loop. Code Leak Detector reads contents and finds a committed credential; this generator prevents the next one. Run the generator on a fresh repository and the detector on anything you inherited. Ready to protect your repo ## Download x2y GitIgnore Generator — generate, audit, and never leak again No account. No telemetry. No cloud. Just a fast, offline tool that keeps your secrets out of Git history and your repositories clean. Get from Microsoft Store Download on itch.io Summary Version | v1.0.0 Platform | Windows Price | Free Telemetry | 0 bytes More from the suite ## Pairs well with ### Code Leak Detector v2.0.5 · WIN · $29 ONE-TIME ### x2y Devs Pad v2.0.0 · WIN · FREE ### x2y Extractor v2.1.0 · WIN · FREE ================================================================================================ PAGE: https://www.x2ydevs.xyz/docs/ TITLE: x2y Devs Tools Documentation | Product Guides META DESCRIPTION: Installation guides, security models, feature references, downloads and changelogs for every x2y Devs Tools offline-first security and developer product. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Getting started Overview Security model Installation Products AV Ultimate v8.5.0 Authenticator v1.0.0 Extractor v2.1.0 GitIgnore Gen v1.0 Devs Pad v2.0.0 SiteDirective v2.0.0 Code Leak Detector v2.0.5 Reference x2y SDK npm Changelog FAQ Support Home / Documentation Search & ask Searches every page of this site — products, documentation, legal & support. Documentation # x2y Devs Tools reference Complete installation guides, feature references, download links and changelogs for every product in the x2y suite. All tools are offline-first, require no account, and collect zero telemetry. Browse on itch.io GitHub SDK reference ## Overview x2y Devs Tools is an independent software company based in Nairobi, Kenya, founded in October 2025 by Moses Gitiriku. The suite comprises eight products spanning Windows desktop applications, an Android mobile app, and a cross-platform Node.js SDK. Every product shares three architectural commitments: - Offline-first. Every feature works without a network connection. If a capability cannot function offline, it does not ship. - Zero telemetry. No analytics, no crash reports, no "improve this product" prompts. Verified at 0 bytes collected since day one. - No accounts. Downloads require no sign-up. Licences do not phone home. Your copy is yours. Seven products remain free under a donationware model. Code Leak Detector has used a one-time $29 licence since 1 September 2026. Suite summary Products | 7 (Windows, Android, Node.js) Founded | October 2025, Nairobi, Kenya Model | Donationware, free since July 2026 Telemetry | 0 bytes — verified continuously Distribution | Microsoft Store, itch.io, GitHub, Uptodown, APKPure, npm Engines | ClamAV, YARA, MalwareBazaar, URLhaus, OpenPhish ## Security model The x2y security model is architectural, not contractual. Privacy is enforced by the absence of network pathways, not by promises. There is no upload endpoint to misuse because none exists. Data policy manifest. Telemetry: 0 bytes collected. Account required: none, ever. Data egress: none by design. Scan engines: ClamAV and YARA (open source). Threat intelligence: MalwareBazaar, URLhaus, OpenPhish. Archive cryptography: AES-256 (Extractor). 2FA storage: on-device encrypted vault with Stealth Mode. Updates: signed releases via GitHub with published SHA-256 checksums. Licence: free since July 2026, donationware. ### Verification Every claim above is independently verifiable. Run any network monitoring tool (Wireshark, Fiddler, mitmproxy, or your operating system's built-in firewall logs) while using any x2y product. You will observe zero outbound connections attributable to the application. All release installers and archives are signed. Published SHA-256 checksums accompany every release on GitHub and itch.io. Verify before installing: PowerShell Get-FileHash .\x2y-av-ultimate-v8.5.0-setup.exe -Algorithm SHA256 # Compare output against the published checksum on the release page ### Open engines and threat intelligence Antivirus scanning in AV Ultimate delegates to ClamAV 0.105 and YARA 4.5 , both open-source projects with public signature feeds. Threat intelligence is sourced from MalwareBazaar (recent and full feeds), URLhaus (malicious URL detection), and OpenPhish (phishing protection). All feeds are downloaded manually and loaded offline — the application itself never connects to these services. ## Installation All x2y products are distributed through Microsoft Store (primary for Windows), itch.io, GitHub Releases, Uptodown, and APKPure (Android). The SDK is available via npm. No product requires an account, email address, or licence key to install and use. ### Windows desktop applications - #### Download the installer Navigate to the product's Microsoft Store page, itch.io page, or GitHub release. Download the .exe installer or portable archive. - #### Verify the checksum Compare the SHA-256 hash of the downloaded file against the published value on the release page. Do not skip this step. - #### Install or extract Run the installer (no administrator privileges required for standard installs) or extract the portable archive to a directory of your choice. - #### Launch No activation, no account creation, no first-run telemetry prompt. The application is ready immediately. ### Android (Authenticator) x2y Authenticator is available on Uptodown and APKPure as an APK. Sideload the APK after enabling installation from unknown sources in your device settings. The app requests no permissions beyond local storage for the encrypted vault. ### Node.js SDK Terminal npm install x2y-dev-tools-sdk The SDK has zero postinstall scripts and no native dependencies. It runs on Node.js 18 and above. Full API reference is available at sdk.x2ydevs.xyz . ## x2y AV Ultimate v8.5.0 WIN 10/11 FREE Comprehensive security suite for Windows. Real-time protection, threat intelligence with 5,500+ signatures, persistence auditing, network monitoring, quarantine vault, and hash lookup. Protects your system without slowing it down. AV Ultimate specifications Version | v8.5.0 Platform | Windows 10, Windows 11 Signatures | 5,500+ (offline bundle) Engines | ClamAV 0.105, YARA 4.5 Threat intel | MalwareBazaar, URLhaus, OpenPhish, ClamAV freshclam Licence | Free, donationware Telemetry | 0 B ### Key features - Real-time threat detection and removal - Threat intelligence with 5,500+ signatures from MalwareBazaar, URLhaus, OpenPhish and ClamAV freshclam - Persistence auditor for startup and registry analysis - Network monitor and quarantine vault - Hash lookup (SHA256 / MD5) ### Quick start CLI x2y-av --scan C:\Projects --engines clamav,yara --report local resolving engines ............ clamav 0.105 · yara 4.5 loading signatures ........... 5,500+ · offline bundle integrity monitor ............ armed · 1,024 watchpaths network egress ............... blocked by design scanning 12,847 files ........ done in 41.2 s ✓ verdict: CLEAN · threats 0 · telemetry sent 0 B ### Downloads Microsoft Store PRIMARY · WIN 10/11 GitHub Releases v8.5.0 · SIGNED itch.io INSTALLER + PORTABLE Uptodown WINDOWS MIRROR APKPure WINDOWS MIRROR ## x2y Authenticator v1.0.0 ANDROID FREE Offline by choice. Secure by design. A high-security offline 2FA vault with Stealth Mode, encrypted Panic Backups, and WiFi Companion for seamless desktop access. 100% offline — no internet required, ever. Authenticator specifications Version | v1.0.0 Platform | Android Storage | On-device encrypted vault Sync | None by design Authentication | PIN + Biometric (fingerprint) Import | Manual entry, QR scan Export | Encrypted Panic Backup via Master QR or .x2y file Licence | Free ### Security features - 100% offline — no internet required ever - Stealth Mode with fake accounts for duress protection - Encrypted Panic Backup with Master QR recovery key - PIN + Biometric (fingerprint) authentication ### Convenience features - WiFi Companion streams codes to PC browser securely over local network - Smart Folders: Work, Finance, Social categorisation - Restore via Master QR or .x2y backup file - NTP Time Sync for accurate TOTP codes ### Downloads GitHub Releases v1.0.0 · APK · SIGNED Uptodown ANDROID MIRROR APKPure ANDROID MIRROR ## x2y Extractor v2.1.0 WIN 10/11 FREE Professional archive manager for Windows that lets you open, browse, extract, create, convert, split, and merge archive files entirely offline. Supports all major formats with full AES-256 password encryption. Extractor specifications Version | v2.1.0 Platform | Windows 10/11 Formats | ZIP, 7Z, RAR (read-only), TAR, GZ, BZ2, XZ, ISO, CAB, WIM, MSI Split archives | .001, .part1 supported Encryption | AES-256 for ZIP/7Z Themes | Light and Dark Licence | Free ### Key features - AES-256 encryption for ZIP and 7Z archives - Create, extract, split and merge operations - Format conversion between archive types - 100% offline — no internet needed ### Downloads Microsoft Store PRIMARY · WIN 10/11 itch.io FREE · INSTALLER ## x2y GitIgnore Generator v1.0 WIN FREE Never commit secrets again. The essential security companion for modern developers. Whether you are working in Python, Node.js, React, or C++, ensuring your sensitive data stays out of your public repositories is critical. Generate the perfect .gitignore file in seconds and audit existing projects for dangerous exposures. GitIgnore Generator specifications Version | v1.0 Platform | Windows Templates | Node.js, Python, React, PHP, Ruby, Rust, C++, macOS, Windows, VSCode, Vim, and more Audit | Existing project exposure scanning Custom | Save and reuse custom templates Licence | Free ### Key features - Stop the "Oops, I committed my .env" nightmare - Audit existing projects for dangerous exposures - Save custom templates for reuse across projects - Generate in seconds, copy to clipboard or save directly ### Downloads Microsoft Store PRIMARY · WINDOWS itch.io FREE · INSTALLER Uptodown WINDOWS MIRROR ## x2y Devs Pad v2.0.0 WIN FREE A professional text editor combining the simplicity of Windows Notepad with powerful tools for coding, scripting, and managing text files. Supports command-line usage, file associations, syntax highlighting for 30+ languages, and advanced editing features. Devs Pad specifications Version | v2.0.0 Platform | Windows CLI | x2ydevspad filename.txt Line nav | x2ydevspad script.py:42 — jumps directly to line 42 Syntax | 30+ languages Auto-Save | Backup system (keeps last 5) Licence | Free ### Core features - Command Line Support: x2ydevspad filename.txt - File Association and Open With integration - Line Number Navigation: x2ydevspad script.py:42 jumps directly to line 42 - Auto-Save with Backup System (keeps last 5 versions) ### Editing features - Syntax Highlighting for 30+ languages - Find and Replace with history - Go to Line (Ctrl+G), Zoom In/Out - Word Wrap toggle, Line Numbers ### Downloads Microsoft Store PRIMARY · WINDOWS itch.io FREE · INSTALLER Uptodown WINDOWS MIRROR ## SiteDirective v2.0.0 WIN FREE A professional-grade desktop application for web developers, SEO specialists, and digital marketers. Built as a high-performance crawling engine, it automates website structure discovery to generate search engine-compliant XML, HTML, JSON, and TXT sitemaps. 100% local processing, zero telemetry. SiteDirective specifications Version | v2.0.0 Platform | Windows Rendering | Full JS rendering engine Sitemaps | XML, HTML, JSON, TXT Crawl depth | 1–10 levels configurable Robots.txt | Built-in architect with custom rules Licence | Free ### Core features - Full website crawling with JavaScript rendering - XML, HTML, JSON, TXT sitemap generation - Robots.txt Architect with custom rule builder - Crawl Depth Control (1–10 levels) ### SEO analysis - Broken Link Detection (404 errors) - Metadata Audit (missing titles and descriptions) - Performance Flagging (heavy pages identified) - 100% local processing, zero telemetry ### Downloads Microsoft Store PRIMARY · WINDOWS itch.io FREE · INSTALLER ## Code Leak Detector v2.0.5 WIN 10/11 Desktop application that scans your entire codebase for accidentally exposed secrets — API keys, tokens, passwords, and other sensitive data. 200+ detection patterns with 100% offline processing. Code Leak Detector is now a paid product $29 one-time One-time $29 licence. No subscriptions, no account required. Code Leak Detector specifications Version | v2.0.5 Platform | Windows 10/11 Patterns | 200+ covering all major platforms Detection | Pattern matching + entropy-based analysis Integrations | Gitleaks, TruffleHog (third-party scanners) Modes | Deep scan (binaries/archives), Learning mode (false positive management) Monitoring | Real-time file watching with instant alerts Memory | Secure handling for sensitive data Processing | 100% offline — no data leaves your machine Licence | $29 one-time ### Key features - 200+ detection patterns covering all major platforms and secret types - 100% offline — no data leaves your machine - Real-time file watching with instant alerts on new exposures - Entropy-based secret detection for custom and uncommon patterns ### Advanced capabilities - Third-party scanner integrations (Gitleaks, TruffleHog) - Deep scan mode for binaries and compressed archives - Learning mode to manage and suppress false positives - Secure memory handling — sensitive data never persisted in plaintext ### Downloads itch.io v2.0.5 · INSTALLER ## x2y SDK npm · stable NODE 18+ FREE Cross-platform Node.js toolkit exposing the same engines behind our desktop tools as programmatic modules: monitor , refactor , secrets , and audit . Offline by default, TypeScript-typed, CI-friendly. ### Installation Terminal npm install x2y-dev-tools-sdk added 1 package in 412 ms · 0 postinstall scripts ### Modules SDK module reference monitor | Uptime, latency, and alert probes for HTTP APIs. Results stored locally. refactor | AST-level code transformations for safe, repeatable refactoring across JavaScript and TypeScript. secrets | Local secret and token scanning with 200+ offline rule patterns. Same engine as Code Leak Detector. audit | Dependency integrity checks, licence compliance, and supply-chain verification. ### Example JavaScript // Scan a working tree for leaked secrets import { secrets } from "x2y-dev-tools-sdk" ; const report = await secrets. scan ( "./src" , { rules: "strict" , egress: "local-only" });console. log (report); // { leaks: 0, rules: 200, runtime: "node:22" } Full API reference. Complete type definitions, module documentation, and integration guides are published at sdk.x2ydevs.xyz . npm x2y-dev-tools-sdk GitHub SOURCE + RELEASES SDK Docs sdk.x2ydevs.xyz ## Changelog A public record of every release across the suite. All releases are signed and accompanied by published SHA-256 checksums on GitHub. Release history Sep 2026 | Code Leak Detector moved to a one-time $29 licence. All other products remain free. Jul 2026 | Entire suite goes free. Paywalls removed across Microsoft Store, itch.io, and GitHub. Jun 2026 | Code Leak Detector v2.0.5 — 200+ patterns, entropy detection, Gitleaks/TruffleHog integration, learning mode. Q2 2026 | SiteDirective v2.0.0 (JS rendering, robots.txt, SEO audit). Extractor v2.1.0 (AES-256, dark theme). Devs Pad v2.0.0 (CLI, auto-save). GitIgnore Generator v1.0. Mar 2026 | Authenticator v1.0.0 (Android, Stealth Mode, WiFi Companion, Panic Backup). AV Ultimate v8.5.0 (5,500+ sigs, persistence auditor). Dec 2025 | AV Ultimate v7.0.0 — new detection pipeline and integrity monitor. Oct 2025 | x2y Devs Tools founded in Nairobi by Moses Gitiriku. First commits of AV Ultimate. ## Frequently asked questions ### Do any x2y products require an internet connection? No. Every product in the suite is fully functional offline. Threat intelligence feeds for AV Ultimate are loaded from manually downloaded bundles. The SDK's npm installation requires a network connection (as all npm installs do), but the package itself makes no network calls at runtime. ### How do I verify that zero telemetry is actually zero? Use any network monitoring tool — Wireshark, Fiddler, GlassWire, or your operating system's firewall logs. Launch any x2y product and observe. You will see zero outbound connections attributable to the application. We encourage this verification. ### Is the Code Leak Detector still free? The free period ended on 1 September 2026 at 00:00 EAT (UTC+3). It now uses a one-time $29 licence. There are no subscriptions, recurring fees, or account requirements. Copies obtained during the free period continue to work indefinitely. ### Can I use x2y products commercially? Yes. All products are free for personal and commercial use under a donationware model. Donations are appreciated but never required. ### Where do I report a security issue? Email security@x2ydevs.xyz . Security disclosures are triaged first. Please include steps to reproduce and affected version numbers. ### What platforms does Authenticator support? x2y Authenticator is an Android application. It is not available on Windows or iOS. The WiFi Companion feature allows streaming TOTP codes to a PC browser over your local network, but the vault itself lives exclusively on the Android device. ## Support We stand behind everything we build. Our support team responds within two working days (EAT, UTC+3). Support channels General | hello@x2ydevs.xyz Security disclosures | security@x2ydevs.xyz Issues & releases | github.com/x2yDevs SDK documentation | sdk.x2ydevs.xyz Office | Nairobi, Kenya · EAT (UTC+3) Contact us Browse all products Overview Security model Installation AV Ultimate Authenticator Extractor GitIgnore Generator Devs Pad SiteDirective Code Leak Detector x2y SDK Changelog FAQ Support ================================================================================================ PAGE: https://www.x2ydevs.xyz/about/ TITLE: About x2y Devs Tools | Offline-First Software META DESCRIPTION: Meet x2y Devs Tools Ltd, the Nairobi software company founded by Moses Gitiriku in 2025 to build offline-first, zero-telemetry security and developer tools. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / About About x2y Devs Tools # Building software that matters. x2y Devs Tools transforms complex problems into elegant solutions. We build desktop applications, mobile apps, and custom software for businesses worldwide. Our work is defined by quality, privacy, and a deep respect for the people who use our tools. Explore our products Work with us NAIROBI, KENYA · HOME OF x2y · 1°17′S 36°49′E 2025 Founded 8 Products shipped 6 Continents served 0 B Telemetry collected Our story ## From a single question to a global practice x2y Devs Tools was founded in October 2025 with a clear purpose: build software that actually helps people. Not bloated applications with features no one uses, but focused tools that solve real problems. The name x2y represents transformation — X is the problem, Y is the solution. Every project we take on follows this principle, taking complex challenges and delivering clean, functional software. Today, x2y Devs Tools continues to grow, serving clients across industries with desktop applications, mobile apps, and custom development services. Our commitment remains unchanged: build well, ship fast, support always. We believe that great software is a partnership between builder and user — and we honour that trust by keeping our tools transparent, offline, and free from hidden agendas. From our headquarters in Nairobi, Kenya, we serve a global audience. Our products are used by independent developers, security teams, and enterprises across six continents. The diversity of our users informs everything we build, ensuring that our tools are practical, reliable, and universally useful. Company facts Legal name | x2y Devs Tools Ltd Founded | October 2025 Headquarters | Nairobi, Kenya Model | Donationware · free since Jul 2026 Platforms | Windows · Android · Node.js Distribution | itch.io · Microsoft Store · GitHub · npm Telemetry | 0 bytes — verified continuously Leadership ## Meet our founder Moses Gitiriku Founder & CEO Moses Gitiriku founded x2y Devs Tools with a vision to create software that developers and businesses can rely on. With deep expertise in software architecture, security, and product design, he leads the company with a hands-on approach to every project. His career spans systems engineering, full-stack development, and open-source contributions, giving him a rare blend of theoretical depth and practical execution. His philosophy is simple: understand the problem deeply, design the solution carefully, and execute with precision. This approach has guided x2y Devs Tools from its founding to become a trusted name in software development. Moses personally reviews every product roadmap and security audit, ensuring that the company's commitment to quality and privacy is upheld at every level. "We don't build software for the sake of building. Every feature serves a purpose. Every line of code earns its place. That's how you create software people actually want to use." — MOSES GITIRIKU · FOUNDER & CEO Facebook LinkedIn Product Hunt Crunchbase Wellfound Dev.to Core principles ## The standards we hold ourselves to → ### Quality over quantity, always We ship fewer things, but we ship them well. Every release undergoes rigorous testing and review before it reaches a user's machine. We would rather delay a launch than compromise on craft. → ### Ship working software, iterate based on feedback We believe in rapid, reliable delivery followed by continuous improvement driven by real use. Each version is a conversation with the people who depend on our tools. → ### Security and performance are non-negotiable Fast, safe software is the baseline, not a premium tier. We build with encryption, integrity verification, and efficiency baked into every layer of the stack. → ### Support the people who use what we build Every user deserves a human response. We answer questions, fix bugs, and listen to suggestions because the relationship does not end at download. What we do ## Focused expertise in software development ### Desktop applications Native Windows applications built for performance, security, and reliability. From system utilities to enterprise software, we engineer solutions that integrate seamlessly with the Windows ecosystem and never require a network connection to function. ### Mobile apps Android applications designed with real users in mind. Clean interfaces, fast performance, and practical functionality — our mobile tools are built to work offline and respect user privacy without accounts or cloud dependencies. ### Custom development Tailored solutions for specific business needs. APIs, integrations, SDKs, and specialised software projects. We work with clients to deliver exactly what they need, on time and within budget, with the same privacy-first principles applied to our own products. Our values ## The principles that guide everything we build ### Security first Protection built into every layer of our software — from encryption to secure defaults, we never compromise on safety. Every tool is auditable and verifiable. ### Performance Fast, efficient software that respects your resources. We optimise for speed and low memory footprint across all platforms, because bloat is a form of disrespect. ### User focused Designed for real people with real needs. We prioritise usability, clarity, and accessibility in every interface, and we test with the workflows our users actually run. ### Support We stand behind everything we build. Our support team is responsive, knowledgeable, and genuinely invested in your success — because trust is earned after the sale. Work with us ## Let's build something that matters Whether you need a custom application built or want to learn more about our products, we'd like to hear from you. Our team is ready to discuss your project and how we can help. Get in touch View our products Contact summary General | hello@x2ydevs.xyz Security | security@x2ydevs.xyz Office | Nairobi, Kenya · EAT Response | Two working days typical ================================================================================================ PAGE: https://www.x2ydevs.xyz/partners/ TITLE: Partners & Ecosystem | x2y Devs Tools META DESCRIPTION: Explore the x2y Devs Tools technology and distribution ecosystem, including Microsoft, GitHub, APKPure, Uptodown and itch.io, or apply to partner. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Partners Grow Together # Partner With Us Join the x2y Devs Tools ecosystem and unlock exclusive benefits. Expand your reach, access our growing community, and build strategic relationships. We work with partners who share our commitment to quality, privacy, and user-centric design. Get In Touch Learn About Us Why Partner ## Why Partner With x2y Devs Tools? x2y Devs Tools has built a reputation for creating quality software and fostering a strong developer community. By partnering with us, you gain access to thousands of engaged users and developers who trust our products. Our partners benefit from our established distribution channels, technical expertise, and brand credibility. Our partnerships are built on mutual success. We invest in our partners' growth and work collaboratively to create value for all stakeholders in our ecosystem. Whether you are a technology provider, a distribution platform, or a community builder, we offer tailored programmes that align with your goals. 6+ Active Distribution Partners 10,000+ Monthly Active Users 50+ Products & Services Global Developer Community Partnership Benefits ## Comprehensive support and resources to drive your success ### Making Apps Build and develop quality software using x2y Devs Tools suite and resources. Access our SDKs, APIs, and documentation to accelerate your development. ### Distribution Access multiple distribution channels to reach your target audience globally. Leverage our partnerships with Microsoft, GitHub, APKPure, and more. ### x2y Tools Leverage our comprehensive toolkit to build, test, and deploy your applications. Our tools are designed for efficiency and reliability. ### Website Get visibility on the x2y Devs platform and dedicated partner showcase. We feature our partners prominently across our digital properties. ### Collaboration Collaborate with our team and community to grow your products together. We share insights, co-develop features, and align roadmaps. ### More Benefits Revenue sharing, co-marketing, community access, and dedicated support. We design partnership packages that drive real value for both sides. Distribution Partners ## Our current distribution partners Microsoft Store GitHub Releases APKPure Android Uptodown Android ShipIt Distribution itch.io Primary These partners help us reach users across Windows, Android, and developer ecosystems worldwide. We are always open to adding new distribution channels that align with our values of privacy and user control. How It Works ## How Partnerships Work 1 ### Reach Out Contact us with your partnership interests — we'll set up an initial conversation to understand your goals. 2 ### Discussion We explore mutual opportunities and benefits, identify synergies, and define a scope that works for both parties. 3 ### Agreement Formalize the partnership terms and scope, including technical integration, marketing, and support commitments. 4 ### Launch Begin collaborating and growing together. We provide ongoing support, co-marketing, and regular check-ins to ensure success. ## Ready to Partner? Let's explore how we can grow together. Reach out to our partnerships team to discuss opportunities that align with your organization. We respond within two working days. Get In Touch Learn About Us ================================================================================================ PAGE: https://www.x2ydevs.xyz/contact/ TITLE: Contact x2y Devs Tools | Support & Partnerships META DESCRIPTION: Contact x2y Devs Tools in Nairobi for general enquiries, product support, responsible security disclosures or partnership applications. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Contact Contact # Talk to a human in Nairobi. Questions about deployment, a security disclosure, or the September licensing change — write to us. We answer in the order messages arrive, and we never add you to a list. Our team is based in Nairobi, Kenya, and we serve users worldwide. - Support support@x2ydevs.xyz — for general help and product queries. - General hello@x2ydevs.xyz — for business and partnership inquiries. - Security disclosures security@x2ydevs.xyz — confidential vulnerability reporting. PGP key available upon request. - WhatsApp +254 782 854 786 — for urgent, non‑technical matters. - Releases & issues github.com/x2ydevs — public repository for bug reports and feature requests. - Office Nairobi, Kenya · —:— EAT (UTC+3) Facebook GitHub LinkedIn Twitter We typically respond within two working days (EAT, UTC+3). Security disclosures are triaged first. If your matter is urgent, please use the WhatsApp number above. Name Please enter your name. Email Please enter a valid email address. TopicGeneral enquirySupportSecurity disclosurePartnership applicationEnterprise & compliancePress Message Please include a short message (10+ characters). Send message No mailing lists, ever. Your message goes to a human inbox in Nairobi. We treat your data with the same respect we give our own. ### Message prepared ✓ Thank you — your message has been prepared. In production this reaches the Nairobi inbox directly. We typically reply within two working days (EAT). You can also reach us directly at support@x2ydevs.xyz or via WhatsApp at +254 782 854 786 . ================================================================================================ PAGE: https://www.x2ydevs.xyz/donate/ TITLE: Support x2y Devs Tools | Donate on Ko-fi META DESCRIPTION: Support the development of x2y Devs Tools' offline-first, zero-telemetry software with an optional one-time or monthly contribution through Ko-fi. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Support Support the project # The tools are free. The work is not. Every x2y product is free and stays free — no paywalls, no subscriptions, no feature gates. Building, maintaining and signing them still costs time, infrastructure and coffee. If our software earns its place on your machine, a contribution on Ko-fi is the simplest way to say thanks and keep the lights on. Support on Ko-fi See our promise No paywalls, ever No account required One-time or monthly Buy me a coffee on Ko-fi Fuel the next release Pick an amount below, or choose your own on Ko-fi. Every contribution goes straight to keeping x2y independent, free and telemetry-free. $3Coffee $5Lunch $10Tools $25Sponsor You'll confirm the exact amount on Ko-fi. Monthly support is optional and cancellable anytime. Support with $5 Payments handled securely by Ko-fi · x2y never sees your card details Our promise ## Donating changes nothing about what you get — because you already get everything We want to be unambiguous: a contribution is a thank-you, not a purchase. It unlocks no features, removes no limits, and creates no tier of users. The software you use today is identical whether you give or not. ### No paywalls, ever Every product remains fully free. We will not move features behind a donation, introduce a "pro" edition, or withhold fixes from non-donors. The suite is and stays complete for everyone. ### Zero telemetry stays zero Supporting us does not opt you into analytics. The software collects nothing, transmits nothing, and that is a contractual commitment under our Terms — not a setting we can flip because you gave. ### No account, no tracking You do not need an x2y account to donate or to use anything. Ko-fi handles the payment; we receive a total, not a profile. Your identity is yours to share or withhold. Where it goes ## How contributions are spent We are a small, self-funded team in Nairobi. Contributions are pooled and spent transparently on the things that keep independent software alive — never on advertising, growth hacks or third-party trackers. - 45% ### Engineering time New features, bug fixes, security patches and signature refreshes across all eight products. This is the largest line, because the work itself is the product. - 25% ### Signing & distribution Code-signing certificates, notarisation, build infrastructure and the fees charged by distribution channels so releases stay trusted and reachable. - 20% ### Threat intelligence & infrastructure Feed access and processing for MalwareBazaar, URLhaus, OpenPhish and ClamAV, plus the servers behind the documentation portals and SDK registry. - 10% ### Reserve & runway A buffer that lets us keep shipping through slow months and absorb unexpected costs without ever reaching for ads or telemetry. Ways to give ## Choose the rhythm that suits you One-time, monthly, or simply spreading the word — every form of support counts. There is no minimum and no obligation. One-time $5or any amount A single coffee to mark the occasion — a bug fix that saved your evening, a scan that caught a leak, a tool that just works. - Pay once, no commitment - Choose any amount on Ko-fi - Optional anonymous message Give once Monthly $5/ month Steady support that makes planning possible. Monthly contributors are the reason we can commit to a release cadence instead of shipping when we can. - Cancel anytime, no questions - Predictable funding for the roadmap - Same software as everyone else Support monthly Non-monetary $0just as valuable Cannot give right now? File an issue, report a false positive, star the repo, or tell a colleague. Attention and feedback keep the project honest. - Report bugs & false positives - Star & share the repositories - Leave a review on the stores Visit GitHub Questions ## Things donors often ask Does donating unlock extra features? No. Every feature is available to every user, free, forever. A contribution is purely a thank-you and a way to fund ongoing work. We will not gate functionality behind donations, now or later. Do you collect my data when I donate? Payment is processed entirely by Ko-fi; x2y never receives or stores your card details. We see only aggregate contribution totals unless you choose to attach a public message. Donating does not enable telemetry in the software — it collects nothing regardless. See our Privacy Policy . Can I give anonymously? Yes. Ko-fi allows you to hide your name from the public feed, and you can leave the optional message blank. There is no x2y account involved at any step. Is the monthly plan really cancellable anytime? Yes. Monthly support is managed through Ko-fi and can be cancelled in a couple of clicks, effective at the end of the current period. No emails to send, no retention calls, and your access to the free software is unaffected either way. My company wants to contribute a larger amount — is that possible? Absolutely, and thank you. For organisational contributions, sponsorship, or invoiced arrangements, reach out at support@x2ydevs.xyz and we will sort out the details. The same rule applies: it funds the work, it buys no special treatment, and the software stays free for all. Is a donation tax-deductible? x2y Devs Tools Ltd is a private company, not a registered charity, so contributions are generally not tax-deductible. Ko-fi provides a receipt for your records. If deductibility matters to you, please consult a tax adviser in your jurisdiction before giving. Thank you ## Whether you give or not — thank you for using x2y Every install, every bug report and every kind word is genuine support. If you can spare the price of a coffee, it goes directly to keeping this suite independent, free and free of telemetry. If you can't, we're glad you're here anyway. Support on Ko-fi Browse the suite Support summary Platform | Ko-fi · ko-fi.com/x2ydevstools Frequency | One-time or monthly Unlocks features? | No — everything stays free Telemetry | 0 bytes — always ================================================================================================ PAGE: https://www.x2ydevs.xyz/privacy/ TITLE: Privacy Policy | x2y Devs Tools META DESCRIPTION: x2y Devs Tools collects no telemetry, requires no accounts, and uses no analytics or tracking cookies. Product data stays on your device. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Privacy Policy Legal # Privacy Policy Our privacy policy is short, because there is very little to say: our products collect nothing, and this website sets no cookies and runs no analytics. Effective date: 21 August 2026 · x2y Devs Tools Ltd · Nairobi, Kenya ## 1. The short version Telemetry: 0 bytes. Accounts: none, ever. Data uploaded: none. Every x2y product is offline-first by architecture. There are no analytics SDKs, no crash reporters, no licence-verification calls and no cloud pipelines — there is simply no endpoint to send anything to. ## 2. What our products store — on your device only - x2y Authenticator keeps your 2FA secrets in an encrypted vault on your device. We cannot read it and never receive it. - x2y AV Ultimate, Code Leak Detector, Extractor, Devs Pad, GitIgnore Generator and SiteDirective write scan reports, quarantined items, archives and settings to your disk only. Decryption keys live in memory for the session and are discarded on close. - The x2y SDK stores monitoring and audit results locally in your project environment. ## 3. What this website collects Nothing. This site is a collection of static pages. It has no forms that submit to our servers, no tracking pixels, no analytics and no cookies. The contact form composes a mailto: message in your own email client — the message travels from you to your mail provider, not to us via this site. ## 4. Third-party requests made by this site The only external requests this site makes are its webfonts, served by the jsDelivr CDN. Product pages ship no third-party images at all: illustrations are inline SVG, and social cards are served from this host. No personal data is attached to those requests. Downloads are hosted by Microsoft Store, itch.io, GitHub, Uptodown and APKPure; when you download from them, their privacy policies apply to that transaction. ## 5. Children’s privacy Our products and website are not directed at children under 13, and we do not knowingly collect any personal data from anyone — of any age. ## 6. Changes to this policy If our practices ever change, this page will be updated first, with a new effective date at the top. Given our architecture, we expect the changes to remain boring. ## 7. Contact Questions about privacy: privacy@x2ydevs.xyz or hello@x2ydevs.xyz . Security disclosures: security@x2ydevs.xyz . ================================================================================================ PAGE: https://www.x2ydevs.xyz/terms/ TITLE: Terms of Use | x2y Devs Tools META DESCRIPTION: Terms for x2y Devs Tools software and website, including licences, acceptable use, warranties, distribution, liability and Kenyan governing law. SITEMAP LASTMOD: 2026-09-21 ------------------------------------------------------------------------------------------------ Home / Terms of Use Legal # Terms of Use The rules for using x2y Devs Tools software and this website — written to be read in two minutes. Effective date: 21 August 2026 · x2y Devs Tools Ltd · Nairobi, Kenya ## 1. Agreement By downloading, installing or using any x2y Devs Tools product, or by using this website, you agree to these terms. If you do not agree, do not use the software or the site. ## 2. Licences - All products are free for personal and commercial use under a donationware model since July 2026. Donations are appreciated, never required. - Code Leak Detector has been available under a one-time $29 licence since 1 September 2026 — no subscriptions, no account. Copies obtained during the free period continue to work indefinitely. - The x2y SDK is released under the MIT licence. ## 3. Acceptable use You may use the products for any lawful purpose. You may not reverse-engineer them to defeat their security features, redistribute modified copies under our name, or use them to analyse systems you do not own or have permission to analyse. ## 4. Open-source components Detection engines and rule sets include ClamAV, YARA, MalwareBazaar, URLhaus, OpenPhish, Gitleaks and TruffleHog formats, each governed by its own licence. Their marks belong to their respective owners. ## 5. Distribution channels Official releases are published on Microsoft Store, itch.io, GitHub, Uptodown and APKPure with signed installers and published SHA-256 checksums. Verify checksums before installing. We are not responsible for copies obtained from other sources. ## 6. Intellectual property The software, this website and the x2y Devs Tools name and logo are the property of x2y Devs Tools Ltd. The licences above grant you rights to use the software; they do not transfer ownership. ## 7. No warranty The products are provided “as is”, without warranty of any kind. No security product can guarantee absolute protection; use defence in depth and keep backups. ## 8. Limitation of liability To the maximum extent permitted by law, x2y Devs Tools Ltd shall not be liable for indirect, incidental or consequential damages arising from the use or inability to use the products. ## 9. Governing law These terms are governed by the laws of the Republic of Kenya. Disputes fall under the jurisdiction of the courts of Nairobi. ## 10. Changes We may update these terms; the effective date above will change accordingly and this page is the sole authoritative version. ## 11. Contact Legal and licensing questions: hello@x2ydevs.xyz . General support: support@x2ydevs.xyz .