I know your only joking here but what you bring up should be a real concern IMO. It doesn't take much for a developer to open the door to security breaches on a system either intentionally or accidentally by not knowing best practices and standards and putting in some vulnerable or bad code. Fortunately the SXI-Q software and underlying components don't appear to require any additional inbound or outbound ports to be enabled on the firewall, unlike some other manufactures that do. Not saying any are vulnerable or not as only a thorough code review could answer that. But for me I'm a little less paranoid with SXI-Q knowing it's not sending / receiving information in the background to the internet.
Yeah one that checks for updates could be dodgy
Not necessarily criminal could just be in cahoots with governments like FB to invade your privacy
Keep tabs on you and build profiles