Security & Data Flows

What the license heartbeat sends

The exact payload your instance sends daily to keep its license current, and what it never includes.

Almost everything about Reqursor Development stays local. The one exception is the license heartbeat: once a day (at a randomized time, not a fixed clock tick), your instance calls license.reqursor.com to refresh its license token. Here's precisely what that call sends.

The payload

FieldWhat it is
instance_idA random identifier generated at first boot, not tied to your hardware or account beyond the license server's own records.
license_idWhich license this instance is activated against.
versionThe installed product version.
os, archOperating system and CPU architecture.
active_usersA count, not a list.
projectsA count of active (non-archived) projects.
runs_24hA count of pipeline runs in the last day.

That's the complete set. Nothing else is sent.

What it never includes

  • No code, no ticket text, no repository names or URLs.
  • No user names or email addresses.
  • No cost, token usage, or model-usage figures beyond the counts above.

What comes back

The response carries a freshly signed license token, plus the server's current signed time. This is used to keep your license valid even if your instance's own clock is wrong, without ever needing to trust a local clock that's jumped forward or been set back.

If daily outbound traffic isn't an option

Enterprise plans support an offline license file in place of the daily heartbeat, for environments that can't call out to the internet at all. Ask about this when you set up. See pricing for what's included at that tier.