Frequently asked questions

Certificates, decryption limits, privacy, and everything else people ask before and after installing Hollowport.

Contact us

Bug reports, feature ideas, or a question the FAQ below doesn't answer — send a message and we'll reply to the email you enter.

Prefer email? Reach us directly at hollowport@hevexa.net.

Frequently asked questions

Do I need a second machine or a Wi-Fi proxy to use this?

No. Hollowport runs entirely on the iPhone as an on-device Network Extension — no laptop tether, no manually configuring a Wi-Fi proxy, no separate cert-install dance on a second device. Install it, trust the certificate once, and you're capturing.

Is there a Mac app?

Yes — a native Mac app is launching alongside the iPhone app, sharing the same investigation engine (Problems, Investigate, Replay, Compare, Collections, Scripting), not a separate product with its own captures. It'll capture directly on Mac with its own Network Extension, or pair with your iPhone to bring its live traffic into the same workspace. Both are launching together, and neither is publicly available yet. Join the waitlist and we'll let you know when that changes.

Why does Hollowport need me to install a certificate?

HTTPS is encrypted end-to-end by design — decrypting it to show you the actual content requires your device to trust a certificate authority that can see it, the same requirement every HTTPS-inspecting tool has, on any platform. See the certificate setup guide for the exact steps.

Is it safe to trust Hollowport's certificate?

The certificate's private key is generated on your device and stored in its Keychain, specifically excluded from iCloud Keychain sync and from unencrypted backups — it never leaves the device, and Hollowport never routes your traffic through a remote server. You're in full control: remove the profile any time under Settings → General → VPN & Device Management, and decryption stops immediately.

Can Hollowport decrypt everything?

Most app traffic, yes. The one exception is certificate-pinned traffic — banking apps, and Apple's own push notifications and iCloud Private Relay — which is visible at the connection level (you'll see it happened, when, and to where) but can't be decrypted. That's a platform limitation that interception tools can't bypass, not something specific to Hollowport. For HTTP/3, DNS-over-HTTPS, DNS-over-TLS, and hostname attribution specifics, see the full Capabilities & Limitations reference.

Can I modify live traffic, not just watch it?

Yes. Breakpoints pause a live request or response so you can edit it by hand; Rules and Mocking automate a targeted change repeatably; Network Chaos simulates bad conditions in one tap. See Rules, Breakpoints, Mocking, and Network Chaos for how each one works.

Does Hollowport support HTTP/3?

Yes — real, end-to-end HTTP/3 (QUIC) capture on ordinary, non-pinned traffic, the same as HTTP/1.1 and HTTP/2. See Capabilities & Limitations for the exact technical picture, including where certificate pinning still applies.

Does Hollowport capture everything, including large responses?

Every captured transaction keeps its complete metadata — method, path, headers, status, and full timing — no matter how large the body is. Body content itself is bounded to 512 KB per request or response: anything larger is captured up to that limit and explicitly marked as truncated in the app, so you always know when you're looking at a partial body rather than the whole thing. That's a deliberate tradeoff for running entirely on your device — bounding potentially huge payloads rather than letting one oversized response consume unlimited storage or memory.

Does capturing traffic drain my battery or slow my phone down?

Running an on-device Network Extension does use some extra battery and CPU while it's active, the same as any VPN-based tool. Tap Stop on the Capture tab when you're not actively debugging, and it's off.

Is my captured traffic sent to Hollowport, Hevexa, or anyone else?

No. There's no account and no server — captured traffic stays in an on-device database and is never uploaded anywhere. See the Privacy Policy for the full picture.

What does "Explain with AI" actually send, and where?

It runs on Apple's on-device model only — never Apple's own cloud fallback (Private Cloud Compute), never a third-party AI service. Credentials and personal data are stripped from the request before it's given to the model.

Does the Scripting feature send my traffic anywhere?

No. A script runs against a snapshot of your already-captured data, entirely on-device — there's no fetch, no network access, and no filesystem access available to it, enforced by the runtime itself and covered by its own test suite. A script can't modify live traffic either; it can only read and summarize what's already been captured.

Can I use this on a work-managed (MDM) device?

On your own device, you're in full control of what you trust. On a company-managed device, installing a VPN configuration or a custom certificate authority may be restricted by your organization's policy, or may need your IT admin's approval — check with them first if Start Capture doesn't work.

How do I stop capturing, or remove the certificate entirely?

Tap Stop on the Capture tab to end the current session. To remove trust entirely, delete the profile under Settings → General → VPN & Device Management on your device — the standard way to remove any installed configuration profile.

Is Hollowport coming to Android?

Not currently — it's built specifically around Apple's on-device Network Extension framework, and there's no Android version planned right now.

Is Hollowport open source?

Not currently — the source isn't public right now.

What will it cost?

Pricing hasn't been finalized yet. Join the waitlist on the home page and we'll let you know at launch.

I found a bug, or have an idea for a feature. Who do I tell?

Email hollowport@hevexa.net or use the contact form above — we read every message ourselves.