What is swtransparencyd, and why is it using the network?
Last updated: 2026-07-31
swtransparencyd is Apple’s daemon for verifying software transparency information used by Apple Intelligence and other clients. Its known baseline is intermittent, daily-level verification activity, but Apple publishes no normal byte range.
What it is
swtransparencyd is Apple’s Software Transparency system daemon. Its registered identifiers include com.apple.swtransparencyd and /usr/libexec/swtransparencyd. It is started by launchd when needed and for scheduled work, so seeing it appear, disappear, or connect periodically does not by itself indicate a problem.
Apple’s supplied manual page says that swtransparencyd verifies “software transparency information” for Apple Intelligence and other clients. In the documented Private Cloud Compute process, this kind of verification helps a client confirm that the software version attested by a cloud node has been recorded in a public, append-only transparency log. The transparency log makes the software claims presented by those nodes auditable and subject to consistency checks.
That scope matters. swtransparencyd is not documented as a general antivirus process that scans every application installed on the Mac. It is also not Gatekeeper or XProtect. Apple refers specifically to software transparency information, so descriptions such as “software integrity checker” can be misleading when they imply that the daemon examines all local software.
Apple has not published the identities or purposes of the “other clients” mentioned in its description. The available documentation also does not provide source code or a complete process-level protocol specification for swtransparencyd. Claims about those clients or undocumented duties therefore remain unverified.
Why it talks to the network
The verified launchd configuration includes a daily maintenance task and a network task for refreshing transparency-log milestones. This establishes a periodic network role even when the daemon is not continuously active.
One documented use appears when Apple Intelligence relies on Private Cloud Compute. Before accepting the cloud system’s software claims, the client needs to verify the node’s software measurements, proof that the relevant entry is included in the transparency log, and consistency of that log. Apple says clients periodically obtain log milestones and reach the Apple Transparency Service through third-party MASQUE proxies. These exchanges concern transparency records, attestations, and related security metadata.
Apple has not published specific hostnames for swtransparencyd, and the research does not establish which endpoint belongs to each process-level connection. It would therefore be inaccurate to invent a domain list or classify an unfamiliar destination solely from the daemon’s name. The exact network behavior of Apple’s unspecified “other clients” is also unverified.
swtransparencyd additionally registers an Apple CloudTelemetry maintenance submission task. That registration alone does not show whether a submission actually occurs, what it would contain, or how much traffic it would generate. Apple has not publicly documented those details, so they should remain labeled unverified rather than being treated as established telemetry behavior.
How much traffic is normal
The verified baseline is intermittent maintenance and verification on a daily timescale, not an uninterrupted transfer. Its known work involves log milestones, proofs, attestations, and security metadata. That describes the purpose and cadence, but it does not establish a normal number of kilobytes or megabytes.
Apple has published neither a typical byte range nor a peak-transfer figure for swtransparencyd. There is consequently no reliable threshold such as “under a certain number of MB per day” that can be applied to every Mac. The presence of scheduled daily work does not imply a known daily data allowance.
Nothing in the verified description identifies swtransparencyd as a video-transfer process, a macOS software updater, or an Apple Intelligence model downloader. A brief connection can fit its documented maintenance role, but sustained heavy traffic deserves separate observation. The process name alone is not enough to decide that a large transfer is normal, malicious, a model download, or an upload of user content.
Can you turn it off
The practical recommendation is to keep swtransparencyd available. Apple does not provide a System Settings switch for disabling this daemon, so there is no supported settings path to follow. Turning off Apple Intelligence might remove one known situation in which software transparency verification is needed, but it does not disable swtransparencyd itself or establish that no other client will request its services.
Forcibly stopping or blocking it may prevent verification of Private Cloud Compute software versions, attestations, or transparency-log consistency. Apple Intelligence requests that depend on cloud computation could then be rejected, fail, or operate in a degraded form. The consequences for Apple’s unspecified “other clients” are unverified because Apple has not identified those clients or explained their dependencies.
What people get wrong
- “It checks whether every installed application is safe.” That overstates its documented role. Apple says
swtransparencydverifies software transparency information; Apple does not describe it as a general malware scanner, Gatekeeper, or XProtect.
- “It controls transparent windows, App Tracking Transparency, or privacy permission prompts.” It does not. “Transparency” here refers to auditable cryptographic transparency logs, not visual effects, tracking permission, or macOS privacy dialogs.
- “
swtransparencydandtransparencydare the same process.” Apple’s local manual pages distinguish them.transparencydprimarily servesidentityservicesd, Messages, and iMessage Contact Key Verification, whileswtransparencydhandles software transparency for Apple Intelligence and other clients.
- “It is useless telemetry, so disabling it cannot affect anything.” The verified primary function is security verification, and Apple provides no supported off switch. A CloudTelemetry maintenance activity is registered, but whether it submits anything, what a submission contains, and how much traffic it uses are all unverified.
- “If it connects, it must be uploading my documents or Apple Intelligence prompts.” There is no reliable evidence for that conclusion. Apple’s documented explanation points to transparency-log data, software attestations, and verification metadata; a network connection alone does not reveal that user content was uploaded.
- “Any large transfer from it must be an AI model download.” Apple does not document
swtransparencydas a model downloader and has not published its normal byte range. If the process appears to sustain substantial traffic, measure and investigate that event instead of assigning a cause from the name alone.
Seeing what it actually used
To move from a process name to evidence, check swtransparencyd in Bytetally’s per-process statistics and observe its traffic across the period in question. Compare a short connection with any sustained transfer you noticed, while remembering that Apple provides no published byte threshold. Treat the measurement as the starting point for further investigation, not as proof of what the transferred data contained.
Related processes
Common questions
What is swtransparencyd on my Mac?
It is Apple’s Software Transparency system daemon. It verifies software transparency information for Apple Intelligence and other clients.
Why is swtransparencyd connecting to the internet?
Known reasons include periodic transparency-log milestone retrieval and verification related to Private Cloud Compute software attestations and log consistency.
Can I disable swtransparencyd?
Apple provides no System Settings switch for disabling it. Blocking it may prevent required Private Cloud Compute verification and cause dependent Apple Intelligence requests to fail, be rejected, or degrade.
Is swtransparencyd uploading my documents or AI prompts?
There is no reliable evidence for that claim. Apple’s published description points to transparency logs, software attestations, and security metadata.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account