Trust center
Security without theater.
Desktop safeguards
- Context isolation, renderer sandboxing, navigation blocking, and narrowly scoped audio-only permissions.
- Secrets encrypted through the operating system when secure storage is available.
- HTTPS-only public services and checkout links; SHA-256 verification before updater launch.
- No automatic external safety reporting and no payment-card storage.
Release integrity
Official releases include checksums, an SBOM, privacy declaration, code-signing status, and build provenance. The current Windows build is not Authenticode-signed; verify its checksum and GitHub attestation.
Report a vulnerability
Use the repository’s private security-advisory channel when available. Never place credentials, private keys, personal records, or exploit details in a public issue. No software is guaranteed perfectly secure.