Self-help
Installing and running ClearVisibility.
The questions people ask before they install, and in the first week after. Checked against the shipping build rather than the brochure, so if an answer here says something ships switched off, it does.
Before you install
What it is, and what it needs.
Desktop and Server. The desktop edition is a single-user application that runs on your own machine with its own private database, and installs into your user profile without administrator rights. The server edition runs as a Windows service with its own private database, is installed by an administrator, and is used by a team over the network. In both cases your estate is held in a database you own.
64-bit Windows, and nothing else. It installs into your local application data folder, needs no administrator rights, and brings its own database, which it creates on first run. It uses the Microsoft WebView2 runtime for its own window: Windows 11 includes that and most Windows 10 machines already have it. Where it is genuinely absent, ClearVisibility opens in your default browser instead.
A 64-bit Windows server, an administrator to run the installer, and one free TCP port for the web interface. The installer brings PostgreSQL 17 with it, bound to 127.0.0.1 and on a port it picks in the 5433 to 5442 range, so there is no database server to buy or provision. IIS is not required.
No. There is no agent. ClearVisibility reads the systems you already run and the management interfaces your Windows machines already expose. Nothing is installed on a target machine and nothing is written to it.
Ten to twenty minutes on modest hardware. Most of that is the database building its indexes over the bundled vulnerability data, which is around 350,000 rows. The installer looks stuck while it does this and is not. The newest file in the install log folder shows it progressing.
Yes, with Azure Trusted Signing. The build refuses to finish if any executable in the package is unsigned, including redistributable components, and it re-checks after signing rather than assuming.
Yes. Community is free with no time limit and needs no card. We do not run separate paid trials, because Community already shows you your estate and its findings.
What it collects
What stays with you, and what reaches us.
Devices and their hardware, operating systems and installed software; user accounts; applications and their installation counts; and anything you import from a file. It turns those into findings about cost, risk, compliance and data quality, with a value against each one where money is involved.
No. It is collected locally, analysed locally and held in your own database. There is no outbound path for inventory anywhere in the product. We hold no copy of it and have no way to read it.
Registration once, a licence check daily, and downloads. Registration sends your organisation name, the contact email address you type in, the name of the machine it is installed on, a randomly generated installation identifier, a one-way hash of those two, and the product version. The daily licence check sends your site reference, that installation identifier and the installation's own credential. Nothing else, and no part of your estate.
No. There is no analytics, usage-tracking or crash-reporting component in either edition, so there is nothing to switch off. We do not receive counts of your devices, users or applications, and we do not record which pages you open or what you search for.
Not unless you switch it on and tell it which ranges. The network scan collector is not even loaded into the application on a default install, and has shipped switched off since August 2026. Nothing probes the wire for unknown hosts until a site turns it on.
Only domains a person has put in scope. A new installation has an empty scope and checks nothing. ClearVisibility will suggest domains it can see in your users' email addresses and your own settings, and a suggestion is never checked until somebody accepts it. The deeper checks that send traffic at your own servers ship switched off and additionally need the specific domain on an authorisation list.
They are listed in full, with what each one receives, on the page about what ClearVisibility does on your network. A site with no outbound access still works: the reference feeds, the threat checks and the licence check all fail quietly and keep the data they already have.
In a private database under your local application data folder, reachable from your own machine only. The application itself listens on 127.0.0.1 and is never a network listener. When you uninstall, you are asked whether to delete the database.
When it will not start
The problems people actually hit.
The old configuration file survived the uninstall but the database was given a fresh password, so the two no longer match. Re-run configure-app.ps1 from the scripts folder in the install directory: it spots the mismatch and re-syncs the connection string only, keeping your other edits. The database log names this one plainly, as a password authentication failure for the application account.
The firewall rule the installer creates covers the Domain and Private network profiles only. If the server's adapter is on the Public profile, inbound traffic is blocked. Check the adapter's profile first, then the rule.
ERR_UNSAFE_PORT means the site was installed on a port browsers block. Change the endpoint in appsettings.Production.json to an ordinary port such as 8090, update the firewall rule, and restart the service. Keep the URL form exactly as http://*:8090, because a malformed one stops the service starting at all.
The scheduler ships switched off, so that a fresh install does not start running nightly passes before anyone has configured the site. Set EventScheduler:Enabled and AgentsEnabled to true in appsettings.Production.json and restart the service. Both are read once, at startup. The Events screen shows whether the scheduler is on and the last hour it ran.
No SMTP server is configured yet. The mail dispatcher ships enabled and idles until you give it a host. Fill in the mail settings and they are picked up on the next poll, with no restart. A blank mail console straight after a restart is normal, because its live status is held in memory.
PDF rendering downloads its own copy of Chromium the first time it runs, which fails on a server with restricted internet access. Install a Chromium or Chrome browser, point Pdf:ChromiumPath at it in appsettings.Production.json, and restart the service. That skips the download entirely.
On a brand-new install the first person to sign in is made the administrator, once, and then that mechanism switches itself off. If the wrong account got there first, sign in as that account. The application log records who was provisioned.
Domain-joined client machines negotiate silently. Three things break it: a workgroup machine, which needs the site added to the browser's integrated authentication list; browsing by a DNS alias, which needs an HTTP service principal name on the machine account; and browsing from the server itself, which can hit the Windows loopback check. Try from a client machine using the server's real hostname.
Almost always because it has nothing to work with yet. Connectors do nothing until credentials are entered, and discovery collectors collect nothing until they are configured. The Connectors console shows the run log, the per-collector last run and the health of each one. An offline host in the discovery log is a harmless skip; a wrong password is a real failure.
On a server, under C:\ProgramData\ClearVisibility\logs: the install transcript, the database log, the application log (one file per day, kept for 30 days) and the discovery run log. On the desktop, under your local application data folder. When a page shows an error it carries a short trace id; search the application log for that id to find the matching server-side entry with its detail.
Export the diagnostics bundle from the tray and send it to us. It is built from files on disk, so it works when the application itself will not, which is the commonest support call we get.
Diagnostics
Getting us what we need, once.
On the desktop edition, right-click the ClearVisibility icon near the clock and choose Export diagnostics, or use the button on the Version page. You choose where the file is saved.
Recent application logs, the database and PostgreSQL logs, your settings with every value whose name looks like a password or a token masked out, and, when the application is running, its content version, estate counts and recent failures. It does not contain the database itself, and it does not contain the stored database password.
No. Nothing uploads it. It is your own data on your own machine: you choose where to save it and whether to send it.
The logs can name devices and users from your estate. The bundle says so in the first lines of its own readme file, so you can read it before deciding to send it.
Not yet. On a server, collect the logs from C:\ProgramData\ClearVisibility\logs and quote the trace id from the error the user was shown. That is enough to find the matching entry.
Community support is on every plan, email support comes with Professional, and Server adds priority support and a named contact. Start with this page and the guides inside the product, then email info@clearvisibility.co.uk.
Licensing
Plans, billing and the grace licence.
Community is free forever. Professional is US$100 a month, or US$1,000 a year, excluding tax. Server is priced by arrangement. Every plan covers unlimited managed devices, and each one builds on the plan below it.
From inside the product. Install ClearVisibility, then choose your plan on the upgrade screen. Our order process is conducted by Paddle, which is the merchant of record: your card details are given to Paddle and we never see or store them. Your licence activates once payment completes.
That is expected, not a fault. When the licence server cannot be reached during setup, which is the normal case for a standalone install, setup finishes on a 60-day grace licence. Re-run registration from Settings once you have connectivity or a registration token. When the grace runs out the application blocks with a licence-expired page, so register before day 60.
Nothing stops working the moment a check fails. Your installation keeps the licence document it already holds until that document's own period, plus 30 days of grace, runs out. One successful check against an active subscription renews it and the tier comes back on its own.
Cancellation stops the next renewal. You keep full access to the end of the period you have already paid for, and the site then returns to Community. Your data is not deleted, and you keep access to it on Community.
Still stuck?
Send us the diagnostics bundle and the trace id from the error, and we can usually tell you what happened without a call.