macOS
- Built with
- SwiftSwiftUI
- Runs on
- Apple silicon
- Built around
- How macOS handles files, permissions and privacy.
Security testing
Hands-on tests. Proof you can reproduce.
All security testingHow we workWhat happens after the first call.See the processBuild
We break software for a living. This is what we build.
All build servicesProof of workOur own apps, built the same way.See themNative software for macOS and Windows that handles files carefully. Plumb, our own Mac app, is written this way.
Fast, dependency-free CLIs with human and JSON output.
Previews, dry runs and a way back before anything irreversible.
Code signing, notarisation and installers, planned from the first build.
Tools we use: Xcode, Visual Studio, nm and otool and Ghidra.
Desktop software can reach files, other apps and sometimes the whole machine. We decide what it may touch before we write it.
Designed against NIST SSDF and OWASP Desktop App Security Top 10.
From install to every run
Install
Notarised on macOS, signed installers on Windows, from your accounts.
Updates
Over HTTPS, verified before they install.
Privilege
No admin password, helper or background service unless a feature needs one.
Files
Symlinks never followed blindly, and a dry run before anything irreversible.
Processes
Validated at the boundary. Each helper does one job.
Web views
No Node in the renderer, isolated contexts, strict CSP.
Yes. A native SwiftUI app for Apple silicon, in development and not on sale yet. It removes nothing without a review and a dry run, and needs no administrator password.
Tauri when a small install and a locked-down renderer matter most. Electron when you need its ecosystem. Either way: no Node in the renderer, a strict CSP, and every message between processes validated.
Mac, Windows or both, and what it may touch on the machine. Then a written quote.
Web and API penetration testingWeb apps and APIs, tested by hand.
Smart contract auditsSolidity, read line by line and fuzzed.
Mobile and desktop app securityAndroid, iOS, macOS and Windows apps.
Network and cloud securityNetworks, plus AWS, GCP and Azure.
Firmware and IoT securityFirmware, device services, updates.
Open-source securityDependencies, pipelines, disclosure.