Frequently Asked Questions
The most common questions about CERNIS PRO — answered briefly and honestly.
What does CERNIS PRO actually do?
It shows which devices are on the home network, who they talk to and whether anything looks unusual — and explains every finding clearly. An honest, understandable overview of one’s own network.
Does CERNIS PRO send my data anywhere?
Not the user’s scans and histories — those stay on their own machine. There is no account, no telemetry and no central CERNIS backend to which scans or usage data are transmitted. Some functions do talk to the internet, because they have to: live monitoring starts with the application and sends check requests to the detected gateways and to two preset internet references at short intervals; the vulnerability cross-check fetches entries for the devices and services found; and blocklists, once switched on, are reloaded regularly. On top of that come requests the user triggers themselves — the external IP check, say, or loading an operator name. As with any access to the internet, at least the connection’s public IP address is visible to the other end. The section “When CERNIS PRO contacts the internet” on the privacy page sets this out.
Do I need an account or a subscription?
No. Download, install, use. No login, no subscription.
Is CERNIS PRO free / open source?
CERNIS PRO is free of charge. The packages shipped are under the GPL-2.0-only, and the source code is available in the download area under “Source code”. Details are on the licence page.
Do I have to be a network expert?
No. The interface is made for interested non-experts, and every function comes with help in plain language. At the same time there is enough depth that professionals get their money’s worth too.
Does CERNIS block or change my network traffic?
No. CERNIS observes and explains — it does not interfere with the traffic. It is an observer, not a firewall.
Why does CERNIS want elevated permissions?
Some deep functions (e.g. passively reading the requested host names) need elevated system permissions. CERNIS says so openly and never takes permissions in secret. Technically, only a tiny, specialised helper carries the required permission — not the whole application.
Does CERNIS see encrypted connections too?
For encrypted connections it sees the target host name (via SNI) and attributes it to the program responsible — not the content. So it is known where an app is talking without the encryption being touched. The live data stays transient; the derived host names are stored permanently only when the recording of external contacts is switched on.
Does it work with my FRITZ!Box?
Yes — CERNIS offers a rich FRITZ!Box detail view via the official TR-064 interface (connection data, DSL, WLAN clients, event log, port forwardings).
Can I create reports?
Yes, six report types as PDF, plus CSV/JSON export — for archiving or sharing.
What happens to my data if I uninstall CERNIS?
It stays where it is. A normal uninstall removes the program, but not personal application data — so scans and settings remain until the user deletes them. The downloads page explains this under the known limitations. There is no copy “somewhere” — everything was and remains local.
Which languages are available?
German and English, switchable at any time — including the built-in manual.
Question not covered? Found a bug?
- General matters: kontakt@cernispro.de
- Security issues: security@cernispro.de
How to report a bug or a security vulnerability well is explained on a dedicated page: Report an issue