Skip to main content

Security

A deliberately small launch surface

Downloading Chowder requires a free account with a verified email address; Standard itself runs with no account or licence once installed. Paddle handles checkout while Clarity Soft owns activation codes and signed entitlements; scans and scan history remain local. Two-factor authentication is available on your download account.

A small, gated identity surface

A verified email account is required only to download Chowder, and gets you nothing beyond that: it never grants Pro, and Standard itself runs with no account once installed. Organisation and administration code stays dormant and excluded from launch routing; any reactivation of that needs a separate security and architecture review.

Local scan data

Desktop scans, file names, detection results, history and quarantine stay on the customer's device. The marketing platform does not receive malware samples or local scan history.

Separated commerce and licence authority

Paddle handles checkout, tax and receipts. Clarity Soft independently issues opaque activation codes and bounded signed entitlement leases. A browser return page never grants Pro, and no merchant API token is shipped to a client.

Safe fallback

Licence expiry, cancellation or a bounded offline failure falls back to Standard. It does not disable basic scanning or delete local history and quarantine.

Clearly labelled downloads

Download pages identify the platform, architecture and test status, and withhold unavailable packages. When a direct artifact is listed, its version and SHA-256 checksum will appear with it. Planned platforms are not presented as available.

Website transport

Production traffic is designed to enter through Cloudflare Tunnel and ModSecurity/OWASP CRS, with HTTPS, HSTS, strict content-security and framing policies. The site will describe these controls as live only after deployment.

Honest scope

Chowder is a graphical malware scanner powered by ClamAV. It is not an EDR product and does not provide Windows kernel-level real-time protection. On Windows it is a companion to Microsoft Defender, not a replacement.