Security policy
Supported beta
Only the exact, non-revoked, versioned, and ultimately approved beta DMG and an explicitly retained rollback release are supported. Local development builds are not public security-supported releases.
Report a vulnerability privately
Use GitHub private vulnerability reporting when it is enabled for the repository. Otherwise, use the private invitation channel only to request a private security route; do not send exploit details there. Never place Mail or Calendar content, credentials, Keychain values, signing secrets, or destructive proof-of-concept data in a public issue.
Coordinated handling
- A critical report suspends the download while authenticity and impact are assessed.
- Reproduction uses synthetic accounts and data plus content-free diagnostics.
- A fix is released only after signing, notarization, Gatekeeper, privacy, SBOM, and regression gates pass again.
- Never repeat an uncertain mutation to demonstrate a vulnerability.
Website security
This staging website uses only static, locally served files: no cookies, analytics, external fonts, or scripts. The server sends noindex, no-store, CSP, frame, referrer, and permissions headers. A download is activated only after the complete release gate passes.