Security

Security at ScaleNinja

We build small, focused tools that touch real user data - APFS snapshots, mounted volumes, files on your disk. Earning the trust to do that is the whole job. Here's how we think about it.

How we approach security.

01

Local-first by default

Our apps do their work on your machine. We don't ship your files, snapshots, or disk metadata to our servers as part of normal operation.

02

Least privilege

We ask for the smallest set of system permissions a feature needs - and explain what each one is for the first time we ask.

03

Signed and notarised

All macOS builds are code-signed with our Apple Developer ID and notarised by Apple before release. Releases are reproducible from a tagged commit.

04

No tracking, no ads

We don't run third-party SDKs inside our apps for advertising, attribution, or session replay. Updates are checked over HTTPS against our own server.

05

Transparent dependencies

We prefer Apple's frameworks and a small, audited set of open-source libraries. Where we use OSS, we honour and link to the original licences.

06

Quick response

We're a small team. That means security reports go straight to the people who wrote the code - not a queue.

App and tool security

Code signing & notarisation

Every macOS build we ship is signed with our Apple Developer ID certificate and notarised by Apple. Gatekeeper will refuse to run a binary that has been tampered with after we sign it. We never ask users to right-click-open or to disable Gatekeeper.

Sandboxing & entitlements

We use the macOS App Sandbox and Hardened Runtime where the feature set allows it. Apps that perform privileged work (for example, mounting or unmounting volumes, managing APFS snapshots) ship with the minimum entitlements needed and are clearly documented. Where elevated privileges are required, the relevant component runs as a small, audited helper rather than as part of the main UI process.

Local-first data handling

Our apps operate on your data locally. When an app reads disk metadata, snapshot information, or files, that work happens on your Mac. Contents never leave your machine unless you explicitly tell the app to send them somewhere you control.

We don't run analytics, telemetry, or crash-reporting SDKs inside our apps that collect identifiable user data. If we ever add opt-in diagnostics for a specific feature, we'll spell it out in the app and in the docs - and it will be off by default.

Software updates

Updates are delivered over HTTPS from our own update endpoint or from the Mac App Store, depending on the product. Update manifests are signed and our update channel verifies signatures before applying anything. We do not ship background services that auto-install code without a user-visible prompt.

Open-source & third-party code

We prefer Apple's first-party frameworks over third-party dependencies. When we do use open-source libraries, we pin versions, review changes before upgrading, and attribute them in the app's "About" or licences screen. We monitor advisories for the libraries we ship.

Website & infrastructure security

Hosting & transport

Our website is hosted on Cloudflare Workers. All traffic to scaleninja.com and our subdomains is served over HTTPS using modern TLS, with HSTS enabled. Cloudflare provides DDoS protection, a Web Application Firewall, and bot management on the edge.

Email & business data

Email and form submissions are received through Google Workspace (Gmail, Google Forms). Internal documents and customer correspondence live in Google Drive / Docs / Sheets, with two-factor authentication required on every account that can access them.

Source control & release

Source code lives in GitHub with branch protection on the main branches and signed commits required for releases. Production secrets (signing keys, API tokens, deploy credentials) are stored in encrypted secret managers - never in the repository.

Payments

Paid products are sold through third-party payment processors and, where applicable, the Mac App Store. We do not see, store, or process your full card details - they go directly to the processor, who is PCI-DSS compliant. We only receive limited transaction metadata needed to issue receipts and meet our accounting obligations. See our Privacy Policy for more.

Responsible disclosure

If you believe you've found a security issue in any ScaleNinja app, tool, or website, please tell us before sharing it publicly. We treat security reports as a top priority and will work with you to understand, reproduce, and fix the issue.

How to report

Email security@scaleninja.com with as much of the following as you can put together:

  • The product name, version, and platform where you saw the issue.
  • A clear description of the vulnerability and its potential impact.
  • Steps to reproduce, ideally with a minimal proof-of-concept.
  • Any logs, screenshots, or recordings that help us see what you saw.
  • Your name or handle, if you'd like to be credited once the issue is fixed.

You can request a PGP key from the same address if you'd like to encrypt your report. For non-security questions, please use support or our contact form instead.

What we ask of you

  • Give us a reasonable amount of time to investigate and ship a fix before any public disclosure - typically up to 90 days, sooner where possible.
  • Don't access, modify, or destroy data that isn't your own.
  • Don't run automated scanners that degrade service or generate excessive traffic against our production systems.
  • Don't perform social engineering, phishing, or physical attacks against ScaleNinja or our users.
  • Follow applicable law.

What you can expect from us

  • An acknowledgement of your report, typically within two business days.
  • Honest communication about whether the issue qualifies, our planned fix, and the timeline.
  • Public credit in the release notes and on a future "Security thanks" page (with your permission).
  • No legal action against good-faith researchers who follow this policy.

We don't currently run a paid bug-bounty program. Researchers who find genuinely impactful issues may receive a thank-you gift or app licences at our discretion - but the main reward is public credit and a real fix shipped quickly.

Out of scope

The following generally do not qualify as security vulnerabilities. Please don't send reports for these unless they're chained into a real impact:

  • Missing security headers without a demonstrable exploit.
  • Reports from automated scanners without proof of impact.
  • Issues affecting only outdated browsers, OS versions, or jailbroken / rooted devices.
  • Self-XSS, clickjacking on pages with no sensitive actions, or "best practice" suggestions.
  • Vulnerabilities in third-party services we use (please report those to the relevant vendor).
  • Denial-of-service via volumetric attacks or resource exhaustion.

Contact

For security reports: security@scaleninja.com. For everything else, see our contact page.

Last updated: June 17, 2026