Kavanati — Security & IT overview

Last updated: 5 October 2026 · describes version 1.11.0

Kavanati processes keystrokes in memory, on the computer, to fix words typed in the wrong keyboard layout. Nothing typed is sent anywhere. The app talks only to kavanati.com: to check for updates, to verify a paid license, and when a user chooses to send feedback. This page lists exactly what it sees, stores and sends, so your security team can verify it.

1. What Kavanati is

A small desktop utility for Windows 10/11 and macOS 12+ (Intel and Apple Silicon) that fixes words typed in the wrong keyboard layout, Hebrew ↔ English. It runs per user, in the background (system tray or menu bar), needs no account, and does all of its work on the computer. There is no cloud processing.

2. What the keyboard access sees

To notice wrong-layout typing as it happens, Kavanati observes key presses system-wide: the same access any spell-checker or keyboard-layout switcher needs.

3. Password fields

Fields that the operating system marks as password fields are skipped entirely: Kavanati doesn't buffer or fix keystrokes there, refuses the manual fix, and doesn't read the field's text. It relies on the system's own marking (IsPassword in Windows UI Automation; secure text fields on macOS).

No application can recognize a secret prompt that the system doesn't mark as a password field, for example a sudo or ssh prompt in a terminal. Typing there is handled like any other typing: processed in memory and never sent. Letters-only words typed there can, however, be counted in the local personal dictionary (section 4), which the user can clear at any time.

4. What is stored on the computer

ItemWhereWhat it contains
Settings%APPDATA%\LangGuard\settings.json
~/.config/LangGuard/settings.json
On/off switches; per-app rules (process names); words the user protected by undoing a fix; the personal dictionary: up to 500 words per language that the user typed and that aren't in the built-in word lists, each with a count; for paid plans, the license key and its signed token; the daily auto-fix counter; the signed plan policy.
Log%APPDATA%\LangGuard\langguard.log
~/langguard.log
App events only: start-up, errors, layout switches, which app was in focus when a fix ran, and counts. No typed text. Cleared every time the app starts and capped at about 512 KB.
Start with the computerWindows: HKCU\Software\Microsoft\Windows\CurrentVersion\Run, value Kavanati
macOS: ~/Library/LaunchAgents/com.melogix.langguard.plist
The path of the app, so it starts at sign-in. Can be turned off in the app's menu.
Start-menu shortcut (Windows)%APPDATA%\Microsoft\Windows\Start Menu\Programs\Kavanati.lnk A shortcut to the app, created once.

Everything is plain text in the user's profile, protected by the operating system like the rest of that profile. "Clear learned words" in the app's Settings menu empties the personal dictionary; deleting the LangGuard folder (the app's original internal name) removes all of it. A developer diagnostic mode that adds typed text to the log exists for development only: it is off unless the environment variable KAVANATI_DEBUG_CONTENT is set to 1 for the user.

5. Every network request

All requests go to kavanati.com over HTTPS (TCP 443). The app contains no analytics, advertising or crash-reporting SDKs.

RequestWhenWhat it carries
Update check
GET /version.json
At start-up, then every 6 hours From version 1.11, three anonymous values: p (platform), v (app version) and first (marks the first check after a new installation), plus a cache-busting timestamp. No identifier and nothing typed. We count these requests in aggregate only.
Update download
GET /Kavanati-windows.exe or /Kavanati-mac.zip
Only when a newer version exists Nothing. The download is checked against the SHA-256 hash in version.json before it is applied.
License (Pro and Business only)
POST /api/license/activate, /refresh, /release
When a key is entered; then at start-up and at most every 12 hours while running. Never on the free plan, and never for licenses activated offline. Activation: license key, device fingerprint, platform and app version. Refresh and release: license key and device fingerprint. The fingerprint is 16 hex characters of a SHA-256 hash of the computer's hardware ID (MachineGuid on Windows, IOPlatformUUID on Mac); the ID itself never leaves the computer.
Feedback, ideas and ratings
(opens kavanati.com/feedback in the browser)
Only when the user chooses Report a problem, Share feedback, or answers the rating prompt Nothing until the user presses Send on the page. A report's example travels in the URL fragment (#), which browsers never send to a server. The feedback page loads no analytics or third-party scripts.
Diagnostic log
POST /api/log
Only if the user agrees, in the Report a problem dialog The local log described in section 4 (app events and app names, no typed text) with a short header of the app's settings and counts.

Blocking kavanati.com doesn't stop Kavanati from fixing typing: updates simply won't arrive, and a paid license keeps working for 30 days between successful checks.

6. Updates and code signing

7. Allow-listing in antivirus and EDR

Because Kavanati installs a keyboard hook and sends synthetic keystrokes, behavior-based EDR tools may flag it as keylogger-like (the technique MITRE ATT&CK calls T1056.001). If you approve it, these are the identifiers to use:

WindowsmacOS
AppKavanati-windows.exe (product name Kavanati), a self-contained .NET single-file executable. It runs from wherever the user saved it, usually Downloads. Kavanati.app, bundle ID com.melogix.langguard, executable Contents/MacOS/Kavanati.Mac, universal (Intel and Apple Silicon).
IdentityNot signed yet: allow by SHA-256 hash (it changes with every release) or by path. Developer ID team LJ373NJ3QV, notarized.
PermissionsStandard user. No admin rights, no driver, no service. Accessibility and Input Monitoring. Not sandboxed; the .NET runtime needs the allow-jit, allow-unsigned-executable-memory and disable-library-validation entitlements.
Self-updateDownloads Kavanati-windows.exe.new next to the app, renames the running file to .old, swaps in the new one and restarts it. Downloads to $TMPDIR/kavanati-update.zip and runs a short script ($TMPDIR/kavanati-update.sh) that replaces the app bundle.
OtherSettings folder %APPDATA%\LangGuard\; single-instance mutex LangGuard.SingleInstance. Runs /usr/sbin/ioreg once at start-up to read the hardware ID for the license fingerprint.
Networkkavanati.com, HTTPS only (section 5).

Rolling it out to a team? See Kavanati for teams. An MSI installer and central deployment with Intune or Group Policy are planned.

8. Reporting a vulnerability

Please email support@kavanati.com with the details and how to reproduce the issue. We read every report and reply as quickly as we can. Our security.txt lists the same contact. The same address answers security questionnaires from organizations.

See also: privacy policy · help & user guide.

← Back to Kavanati