Security policy

Supported beta

Only the exact, non-revoked, versioned, and ultimately approved beta DMG and an explicitly retained rollback release are supported. Local development builds are not public security-supported releases.

Report a vulnerability privately

Use GitHub private vulnerability reporting when it is enabled for the repository. Otherwise, use the private invitation channel only to request a private security route; do not send exploit details there. Never place Mail or Calendar content, credentials, Keychain values, signing secrets, or destructive proof-of-concept data in a public issue.

Coordinated handling

Website security

This staging website uses only static, locally served files: no cookies, analytics, external fonts, or scripts. The server sends noindex, no-store, CSP, frame, referrer, and permissions headers. A download is activated only after the complete release gate passes.