Security and data handling
Install the CLI with the terminal installer. It writes the binary directly, so macOS attaches no quarantine flag. The macOS binary has an ad hoc signature and is not notarized by Apple, so a copy downloaded through a browser, which does carry com.apple.quarantine, is killed on launch with exit status 137 and no error message. Re-run the installer, or clear the flag with xattr -d com.apple.quarantine ./vanish, before running such a copy. The installer and the self-updater verify each archive's SHA-256 checksum from the release; the checksum comes from the same host as the archive, so it does not authenticate the publisher independently of that host.
Vanish runs commands on managed AWS Linux workers. Each worker serves one Run and is terminated afterward. Workers have outbound internet access, so your command can send data to outside services.
The client excludes credential paths, private keys, and the .env family from stored snapshots. Run-scoped .env files travel to the worker separately and die with that worker. If your command copies a secret into an ordinary output file, that file is ordinary result data; Vanish does not detect secrets by content.
Stored data is scoped to your account, encrypted in transit with TLS, and encrypted at rest in S3. Worker disks are encrypted. This is not end-to-end encryption: Vanish, as the operator of the service, can read what you send it. A compromised laptop or a malicious local agent can act with your local credentials. Dependencies downloaded inside a Run remain part of your supply-chain risk.
Inspect staged changes before you apply them. vanish results rm TOKEN --dry-run shows which staged result would be deleted. Deleting a staged result removes your local copy, not the archive Vanish keeps for the Run.
Analytics
The Vanish CLI sends no usage reports, telemetry or diagnostics. Its network traffic is the work itself: signing in, and sending each Run's command and files to Vanish. It also checks downloads.vanishcompute.com for a new release at most once a day and installs it the next time it starts. Set VANISH_UPDATES=warn to be told about new releases instead, or VANISH_UPDATES=disabled to stop checking.
This website is measured. vanishcompute.com and the account pages load
PostHog and record which pages were viewed, whether the install command was
copied, and the campaign parameters in the link you arrived through, so we
can tell whether an advertisement brought anyone. Session replay is switched
off, surveys are switched off, and Do Not Track is honoured.
To turn it off for your browser, run this in the developer console on the site:
vanishAnalytics.optOut()Product numbers, such as accounts, Runs, failures, latency and credits, are counted by the Vanish service, which already holds those records because it performed the work. They are never collected from your machine, and they never include the content of a command or its output.
Reporting a vulnerability
To report a suspected vulnerability in the Vanish CLI, managed service, or website, email security@vanishcompute.com privately. Do not post vulnerability details anywhere public, including the Discord.
Include the affected component and version, a short description of the impact, and the smallest reproduction you can provide safely. Remove credentials, personal data, and other users' data from examples and logs. For sensitive material, first ask how to transfer it securely. Coordinate public disclosure through the private report thread.