The agent is open source
The agent runs as root on your servers and reads your backups, so you should be able to see exactly what it does. Its code is public under the Apache License 2.0. The dashboard server is a paid product.
Source code
Read it, audit it, build it yourself. The agent only collects facts and runs the checks the server asks for — it never opens a port and never sends your files anywhere.
Download the source (106)Apache License 2.0 · © Vaultwitness authors
Build it yourself
- Install Go (any recent version — the build below fetches the exact one we use).
- Unpack the source of the version your server runs:
$ tar xzf vaultwitness-agent-106-src.tar.gz$ cd vaultwitness-agent-106-src
- Build it exactly as we do:
$ CGO_ENABLED=0 GOOS=linux GOARCH=amd64 GOTOOLCHAIN=go1.23.4 \go build -trimpath -buildvcs=false \-ldflags "-s -w -X github.com/insoftcompany/vaultwitness/internal/version.Version=106" \-o vaultwitness-agent ./cmd/agent
- Compare with ours:
sha256sum vaultwitness-agentgives exactly the checksum of the release below. - Using your own build? Turn off Update the agent automatically in that host's settings, or the server will replace it with its own copy.
Agent releases
| Version | Date | What changed | |
|---|---|---|---|
| 106 | 2026-09-29 | First public release under the name Vaultwitness. Updates itself from your server. A new server shows "Checking" while its first check runs. | linux-amd64 · sha256 · source |
Every release has its program, checksum and source side by side. The agent's checksum for 106 is 8071a09e8e7070099d751b25ac54b3d05b67c15f259aeb3a452a716d12b110ee.