# The security scanner, and what it does not check

Settings, System, Safety, Security events runs a prompt-injection scanner on content flowing through agent turns. It is not a scan of everything in your vault, and the app says so in its own words.

*https://perpetualtechnologies.co.uk/support/what-the-injection-scanner-does-not-cover — last checked 2026-09-08*

## Steps

1. Open Settings, then System, then Safety, then the Security events row, then Review.
2. The page lists what it actually scans: content that flows through a tool result or an agent turn, and wire messages once they enter one.
3. It also lists, in its own words, what it does not cover: your vault at rest unless content is actively flowing through a turn, anything past the first 128 KiB of a single input, your own typed chat messages, and camera or OS-login intrusion detection.

## How to tell it worked

The page itself states both lists rather than leaving either to be assumed.

## If it does not work

**You assumed importing or writing a note scans it for injected instructions.**

It does not. Vault content is only scanned when it flows through a tool result or an agent context, not on write or import.

**You pasted a very long document and want to know if all of it was checked.**

Only the first 128 KiB of any single input is scanned. Content beyond that is not.

## Related guides

- [The Safety screen: rewrites, security events and audit logs](https://perpetualtechnologies.co.uk/support/safety-queues)
- [Connect an MCP server](https://perpetualtechnologies.co.uk/support/connect-an-mcp-server)

## Still stuck

Bug reports belong in the app, in Settings, About. Those carry no contact details, so they
get fixed rather than answered. To get a reply, email us instead: that route targets two
business days. https://perpetualtechnologies.co.uk/contact
