Kavanati — Security & IT overview
Last updated: 5 October 2026 · describes version 1.11.0
1. What Kavanati is
A small desktop utility for Windows 10/11 and macOS 12+ (Intel and Apple Silicon) that fixes words typed in the wrong keyboard layout, Hebrew ↔ English. It runs per user, in the background (system tray or menu bar), needs no account, and does all of its work on the computer. There is no cloud processing.
2. What the keyboard access sees
To notice wrong-layout typing as it happens, Kavanati observes key presses system-wide: the same access any spell-checker or keyboard-layout switcher needs.
- Windows: a low-level keyboard hook (
SetWindowsHookEx,WH_KEYBOARD_LL), a low-level mouse hook used only to notice clicks (a click resets its buffer), and focus-change events. For each key press it uses the virtual-key code, the active keyboard layout and the name of the foreground process. - macOS: a Quartz event tap for key presses, modifier changes and mouse clicks. macOS requires the user to grant Accessibility and Input Monitoring for this.
- Held in memory only: the word being typed, up to six earlier words from the same burst of typing (so a whole-line fix can reach them) and the last fix (so it can be undone). These are cleared when the user presses Enter, clicks, switches apps, uses navigation keys or shortcuts, and after two minutes without typing.
- Field context: to judge which language a field is written in, Kavanati can read the focused field's current text through the operating system's accessibility interface (UI Automation on Windows, the Accessibility API on macOS). That text is examined in memory and is never stored or sent.
- Making a fix: it sends backspaces and the corrected characters as synthetic key events
(
SendInput/CGEventPost) and switches the keyboard layout. The manual whole-line fix copies the current line through the clipboard, converts it, pastes it back and then restores the previous clipboard text. Clipboard-history tools (such as Windows clipboard history) may record that line.
3. Password fields
Fields that the operating system marks as password fields are skipped entirely: Kavanati doesn't buffer or fix
keystrokes there, refuses the manual fix, and doesn't read the field's text. It relies on the system's own marking
(IsPassword in Windows UI Automation; secure text fields on macOS).
No application can recognize a secret prompt that the system doesn't mark as a password field, for example a
sudo or ssh prompt in a terminal. Typing there is handled like any other typing: processed in
memory and never sent. Letters-only words typed there can, however, be counted in the local personal dictionary
(section 4), which the user can clear at any time.
4. What is stored on the computer
| Item | Where | What it contains |
|---|---|---|
| Settings | %APPDATA%\LangGuard\settings.json~/.config/LangGuard/settings.json |
On/off switches; per-app rules (process names); words the user protected by undoing a fix; the personal dictionary: up to 500 words per language that the user typed and that aren't in the built-in word lists, each with a count; for paid plans, the license key and its signed token; the daily auto-fix counter; the signed plan policy. |
| Log | %APPDATA%\LangGuard\langguard.log~/langguard.log |
App events only: start-up, errors, layout switches, which app was in focus when a fix ran, and counts. No typed text. Cleared every time the app starts and capped at about 512 KB. |
| Start with the computer | Windows: HKCU\Software\Microsoft\Windows\CurrentVersion\Run, value
KavanatimacOS: ~/Library/LaunchAgents/com.melogix.langguard.plist |
The path of the app, so it starts at sign-in. Can be turned off in the app's menu. |
| Start-menu shortcut (Windows) | %APPDATA%\Microsoft\Windows\Start Menu\Programs\Kavanati.lnk |
A shortcut to the app, created once. |
Everything is plain text in the user's profile, protected by the operating system like the rest of that profile.
"Clear learned words" in the app's Settings menu empties the personal dictionary; deleting the
LangGuard folder (the app's original internal name) removes all of it. A developer diagnostic mode that
adds typed text to the log exists for development only: it is off unless the environment variable
KAVANATI_DEBUG_CONTENT is set to 1 for the user.
5. Every network request
All requests go to kavanati.com over HTTPS (TCP 443). The app contains no analytics, advertising or crash-reporting SDKs.
| Request | When | What it carries |
|---|---|---|
Update checkGET /version.json | At start-up, then every 6 hours | From version 1.11, three anonymous values: p (platform), v (app version) and
first (marks the first check after a new installation), plus a cache-busting timestamp. No
identifier and nothing typed. We count these requests in aggregate only. |
Update downloadGET /Kavanati-windows.exe or /Kavanati-mac.zip |
Only when a newer version exists | Nothing. The download is checked against the SHA-256 hash in version.json before it is
applied. |
License (Pro and Business only)POST /api/license/activate, /refresh,
/release |
When a key is entered; then at start-up and at most every 12 hours while running. Never on the free plan, and never for licenses activated offline. | Activation: license key, device fingerprint, platform and app version. Refresh and release: license key and device fingerprint. The fingerprint is 16 hex characters of a SHA-256 hash of the computer's hardware ID (MachineGuid on Windows, IOPlatformUUID on Mac); the ID itself never leaves the computer. |
| Feedback, ideas and ratings (opens kavanati.com/feedback in the browser) |
Only when the user chooses Report a problem, Share feedback, or answers the rating prompt | Nothing until the user presses Send on the page. A report's example travels in the URL fragment
(#), which browsers never send to a server. The feedback page loads no analytics or third-party
scripts. |
Diagnostic logPOST /api/log |
Only if the user agrees, in the Report a problem dialog | The local log described in section 4 (app events and app names, no typed text) with a short header of the app's settings and counts. |
Blocking kavanati.com doesn't stop Kavanati from fixing typing: updates simply won't arrive, and a paid license keeps working for 30 days between successful checks.
6. Updates and code signing
- Every release publishes the SHA-256 hashes of both builds in
version.json. The app downloads an update in the background, verifies it against that hash and discards it on a mismatch; the update is applied when the user restarts the app.version.jsonis served over HTTPS; apart from the plan policy inside it, which is signed, it isn't separately signed yet. - macOS: signed with an Apple Developer ID (team
LJ373NJ3QV), hardened runtime, notarized by Apple and stapled. To check:spctl -a -vv /Applications/Kavanati.app. - Windows: the executable isn't code-signed yet, so SmartScreen asks for confirmation on first run and Smart
App Control or a company policy may block it. Distribution through the Microsoft Store, which signs the app, is
planned. Until then, download only from kavanati.com and compare the file's hash with
version.json:Get-FileHash .\Kavanati-windows.exe.
7. Allow-listing in antivirus and EDR
Because Kavanati installs a keyboard hook and sends synthetic keystrokes, behavior-based EDR tools may flag it as keylogger-like (the technique MITRE ATT&CK calls T1056.001). If you approve it, these are the identifiers to use:
| Windows | macOS | |
|---|---|---|
| App | Kavanati-windows.exe (product name Kavanati), a self-contained .NET single-file
executable. It runs from wherever the user saved it, usually Downloads. |
Kavanati.app, bundle ID com.melogix.langguard, executable
Contents/MacOS/Kavanati.Mac, universal (Intel and Apple Silicon). |
| Identity | Not signed yet: allow by SHA-256 hash (it changes with every release) or by path. | Developer ID team LJ373NJ3QV, notarized. |
| Permissions | Standard user. No admin rights, no driver, no service. | Accessibility and Input Monitoring. Not sandboxed; the .NET runtime needs the allow-jit, allow-unsigned-executable-memory and disable-library-validation entitlements. |
| Self-update | Downloads Kavanati-windows.exe.new next to the app, renames the running file to
.old, swaps in the new one and restarts it. |
Downloads to $TMPDIR/kavanati-update.zip and runs a short script
($TMPDIR/kavanati-update.sh) that replaces the app bundle. |
| Other | Settings folder %APPDATA%\LangGuard\; single-instance mutex
LangGuard.SingleInstance. |
Runs /usr/sbin/ioreg once at start-up to read the hardware ID for the license fingerprint. |
| Network | kavanati.com, HTTPS only (section 5). | |
Rolling it out to a team? See Kavanati for teams. An MSI installer and central deployment with Intune or Group Policy are planned.
8. Reporting a vulnerability
Please email support@kavanati.com with the details and how to reproduce the issue. We read every report and reply as quickly as we can. Our security.txt lists the same contact. The same address answers security questionnaires from organizations.
See also: privacy policy · help & user guide.
כוונתי — סקירת אבטחה ו‑IT
עדכון אחרון: 5 באוקטובר 2026 · מתאר את גרסה 1.11.0
1. מה זה כוונתי
תוכנת שירות קטנה ל‑Windows 10/11 ול‑macOS 12 ומעלה (Intel ו‑Apple Silicon) שמתקנת מילים שהוקלדו בפריסת מקלדת שגויה, עברית ↔ אנגלית. היא רצה לכל משתמש בנפרד, ברקע (באזור ההודעות או בשורת התפריטים), לא דורשת חשבון ועושה את כל העבודה על המחשב. אין עיבוד בענן.
2. מה הגישה למקלדת רואה
כדי לזהות הקלדה בשפה הלא נכונה בזמן אמת, כוונתי מאזין להקשות בכל המערכת: אותה גישה שכל בודק איות או מחליף פריסות צריך.
- Windows: הוק מקלדת ברמה נמוכה (
SetWindowsHookEx,WH_KEYBOARD_LL), הוק עכבר ברמה נמוכה שמשמש רק לזיהוי לחיצות (לחיצה מאפסת את המאגר), ואירועי שינוי פוקוס. בכל הקשה הוא משתמש בקוד המקש, בפריסת המקלדת הפעילה ובשם התהליך שבחזית. - macOS: event tap של Quartz להקשות, לשינויי מקשי Shift/Ctrl וללחיצות עכבר. macOS מחייבת שהמשתמש יאשר הרשאות נגישות וניטור קלט.
- נשמר בזיכרון בלבד: המילה שמוקלדת כרגע, עד שש מילים קודמות מאותו רצף הקלדה (כדי שתיקון שורה שלמה יגיע אליהן) והתיקון האחרון (כדי שאפשר יהיה לבטל אותו). כל אלה מתאפסים בלחיצה על Enter, בלחיצת עכבר, במעבר בין אפליקציות, במקשי ניווט ובקיצורי מקשים, ואחרי שתי דקות בלי הקלדה.
- הקשר של השדה: כדי להבין באיזו שפה כתוב השדה, כוונתי יכול לקרוא את הטקסט הנוכחי של השדה שבפוקוס דרך ממשק הנגישות של מערכת ההפעלה (UI Automation ב‑Windows, Accessibility API ב‑macOS). הטקסט נבדק בזיכרון ולעולם לא נשמר או נשלח.
- ביצוע תיקון: הוא שולח מחיקות ואת התווים המתוקנים כהקשות סינתטיות (
SendInput/CGEventPost) ומחליף את פריסת המקלדת. תיקון שורה שלמה ידני מעתיק את השורה דרך הלוח (clipboard), ממיר, מדביק בחזרה ואז מחזיר ללוח את התוכן הקודם. כלים ששומרים היסטוריית לוח (כמו היסטוריית הלוח של Windows) עשויים לשמור את השורה.
3. שדות סיסמה
שדות שמערכת ההפעלה מסמנת כשדות סיסמה מדולגים לגמרי: כוונתי לא שומר במאגר ולא מתקן הקשות שם, מסרב לתיקון הידני,
ולא קורא את הטקסט של השדה. הוא נשען על הסימון של המערכת עצמה (IsPassword ב‑UI Automation של Windows;
שדות טקסט מאובטחים ב‑macOS).
אף אפליקציה לא יכולה לזהות בקשת סוד שהמערכת לא מסמנת כשדה סיסמה, למשל בקשת sudo או
ssh בטרמינל. הקלדה שם מטופלת כמו כל הקלדה אחרת: מעובדת בזיכרון ולעולם לא נשלחת. עם זאת, מילים
שמורכבות מאותיות בלבד ומוקלדות שם עלולות להיספר במילון האישי המקומי (סעיף 4), שהמשתמש יכול לנקות בכל רגע.
4. מה נשמר במחשב
| פריט | מיקום | תוכן |
|---|---|---|
| הגדרות | %APPDATA%\LangGuard\settings.json~/.config/LangGuard/settings.json |
מתגי הפעלה; כללים לפי אפליקציה (שמות תהליכים); מילים שהמשתמש הגן עליהן בביטול תיקון; המילון האישי: עד 500 מילים בכל שפה שהמשתמש הקליד ושאינן ברשימות המילים המובנות, כל אחת עם מונה; במסלולים בתשלום, מפתח הרישיון והאסימון החתום שלו; מונה התיקונים האוטומטיים היומי; מדיניות התוכנית החתומה. |
| יומן | %APPDATA%\LangGuard\langguard.log~/langguard.log |
אירועי אפליקציה בלבד: הפעלה, שגיאות, החלפות פריסה, איזו אפליקציה הייתה בפוקוס כשרץ תיקון, ומונים. בלי טקסט שהוקלד. מתרוקן בכל הפעלה של האפליקציה ומוגבל לכ‑512KB. |
| עלייה עם המחשב | Windows: HKCU\Software\Microsoft\Windows\CurrentVersion\Run, ערך
KavanatimacOS: ~/Library/LaunchAgents/com.melogix.langguard.plist |
הנתיב של האפליקציה, כדי שתעלה עם הכניסה למחשב. אפשר לכבות בתפריט האפליקציה. |
| קיצור דרך בתפריט התחל (Windows) | %APPDATA%\Microsoft\Windows\Start Menu\Programs\Kavanati.lnk |
קיצור דרך לאפליקציה, שנוצר פעם אחת. |
הכל נשמר כטקסט רגיל בפרופיל של המשתמש, ומוגן על ידי מערכת ההפעלה כמו שאר הפרופיל. "Clear learned words" בתפריט
ההגדרות של האפליקציה מרוקן את המילון האישי; מחיקת התיקייה LangGuard (השם הפנימי המקורי של האפליקציה)
מוחקת הכל. קיים מצב אבחון למפתחים שמוסיף ליומן טקסט מוקלד, לצורכי פיתוח בלבד: הוא כבוי, אלא אם משתנה הסביבה
KAVANATI_DEBUG_CONTENT מוגדר ל‑1 עבור המשתמש.
5. כל בקשות הרשת
כל הבקשות נשלחות ל‑kavanati.com ב‑HTTPS (פורט TCP 443). באפליקציה אין רכיבי אנליטיקס, פרסום או דיווח קריסות.
| בקשה | מתי | מה היא נושאת |
|---|---|---|
בדיקת עדכוניםGET /version.json | בהפעלה, ואז כל 6 שעות | מגרסה 1.11, שלושה ערכים אנונימיים: p (פלטפורמה), v (גרסת האפליקציה) ו‑first
(מסמן את הבדיקה הראשונה אחרי התקנה חדשה), וחותמת זמן למניעת מטמון. בלי מזהה ובלי שום דבר שהוקלד. אנחנו סופרים
את הבקשות האלה רק במצטבר. |
הורדת עדכוןGET /Kavanati-windows.exe או /Kavanati-mac.zip |
רק כשיש גרסה חדשה יותר | שום דבר. הקובץ שירד נבדק מול חתימת ה‑SHA-256 שב‑version.json לפני שהוא מותקן. |
רישיון (Pro ולעסקים בלבד)POST /api/license/activate, /refresh,
/release |
כשמזינים מפתח; אחר כך בהפעלה, ולכל היותר פעם ב‑12 שעות בזמן ריצה. אף פעם במסלול החינמי, ואף פעם ברישיון שהופעל אופליין. | הפעלה: מפתח הרישיון, טביעת מכשיר, פלטפורמה וגרסת האפליקציה. רענון ושחרור: מפתח הרישיון וטביעת המכשיר. הטביעה היא 16 תווים הקסדצימליים מתוך hash מסוג SHA-256 של מזהה החומרה של המחשב (MachineGuid ב‑Windows, IOPlatformUUID ב‑Mac); המזהה עצמו לא יוצא מהמחשב. |
| משוב, רעיונות ודירוג (פותח את kavanati.com/feedback בדפדפן) |
רק כשהמשתמש בוחר בדיווח על בעיה, בשיתוף משוב, או עונה לבקשת הדירוג | שום דבר, עד שהמשתמש לוחץ שליחה בעמוד. הדוגמה שמצורפת לדיווח עוברת בחלק ה‑# של הכתובת, שדפדפנים
לעולם לא שולחים לשרת. בעמוד המשוב אין אנליטיקס ואין סקריפטים של צד שלישי. |
יומן אבחוןPOST /api/log |
רק אם המשתמש מסכים, בחלון הדיווח על בעיה | היומן המקומי שמתואר בסעיף 4 (אירועי אפליקציה ושמות אפליקציות, בלי טקסט שהוקלד) עם כותרת קצרה של הגדרות האפליקציה והמונים. |
חסימת kavanati.com לא מונעת מכוונתי לתקן הקלדה: פשוט לא יגיעו עדכונים, ורישיון בתשלום ממשיך לעבוד 30 יום בין בדיקות מוצלחות.
6. עדכונים וחתימה דיגיטלית
- כל גרסה מפרסמת ב‑
version.jsonאת חתימות ה‑SHA-256 של שתי הגרסאות. האפליקציה מורידה עדכון ברקע, בודקת אותו מול החתימה ומוחקת אותו אם יש אי‑התאמה; העדכון מותקן כשהמשתמש מפעיל את האפליקציה מחדש.version.jsonמוגש ב‑HTTPS; מלבד מדיניות התוכנית שבתוכו, שחתומה, הוא עוד לא חתום בנפרד. - macOS: חתום ב‑Apple Developer ID (צוות
LJ373NJ3QV), עם hardened runtime, מאושר (notarized) על ידי Apple ועם ticket מוטמע. לבדיקה:spctl -a -vv /Applications/Kavanati.app. - Windows: הקובץ עוד לא חתום דיגיטלית, ולכן SmartScreen מבקש אישור בהפעלה הראשונה, ו‑Smart App Control או
מדיניות ארגונית עלולים לחסום אותו. הפצה דרך Microsoft Store, שחותמת את האפליקציה, בתכנון. עד אז, הורידו רק
מ‑kavanati.com והשוו את ה‑hash של הקובץ ל‑
version.json:Get-FileHash .\Kavanati-windows.exe.
7. רשימות היתרים באנטי־וירוס וב‑EDR
מכיוון שכוונתי מתקין הוק מקלדת ושולח הקשות סינתטיות, כלי EDR שמבוססים על התנהגות עלולים לסמן אותו כדומה לקילוגר (הטכניקה ש‑MITRE ATT&CK מכנה T1056.001). אם אתם מאשרים אותו, אלה המזהים:
| Windows | macOS | |
|---|---|---|
| אפליקציה | Kavanati-windows.exe (שם המוצר Kavanati), קובץ .NET יחיד ועצמאי. רץ מהמקום שבו
המשתמש שמר אותו, בדרך כלל תיקיית ההורדות. |
Kavanati.app, מזהה חבילה com.melogix.langguard, קובץ הרצה
Contents/MacOS/Kavanati.Mac, אוניברסלי (Intel ו‑Apple Silicon). |
| זהות | עוד לא חתום: אשרו לפי hash מסוג SHA-256 (משתנה בכל גרסה) או לפי נתיב. | צוות Developer ID LJ373NJ3QV, מאושר (notarized). |
| הרשאות | משתמש רגיל. בלי הרשאות מנהל, בלי דרייבר ובלי שירות. | נגישות וניטור קלט. לא בארגז חול (sandbox); סביבת .NET דורשת את ההרשאות allow-jit, allow-unsigned-executable-memory ו‑disable-library-validation. |
| עדכון עצמי | מוריד את Kavanati-windows.exe.new ליד האפליקציה, משנה את שם הקובץ הרץ
ל‑.old, מחליף ומפעיל מחדש. |
מוריד אל $TMPDIR/kavanati-update.zip ומריץ סקריפט קצר
($TMPDIR/kavanati-update.sh) שמחליף את חבילת האפליקציה. |
| שונות | תיקיית הגדרות %APPDATA%\LangGuard\; mutex למופע יחיד
LangGuard.SingleInstance. |
מריץ את /usr/sbin/ioreg פעם אחת בהפעלה כדי לקרוא את מזהה החומרה לטביעת הרישיון. |
| רשת | kavanati.com, ב‑HTTPS בלבד (סעיף 5). | |
פורסים לצוות? ראו כוונתי לעסקים. התקנת MSI ופריסה מרוכזת ב‑Intune או ב‑Group Policy בתכנון.
8. דיווח על חולשת אבטחה
כתבו ל‑support@kavanati.com עם הפרטים ואיך לשחזר את הבעיה. אנחנו קוראים כל דיווח ועונים מהר ככל האפשר. קובץ security.txt שלנו מפנה לאותה כתובת. אותה כתובת עונה גם על שאלוני אבטחה של ארגונים.
ראו גם: מדיניות הפרטיות · מדריך השימוש.