01
Local-first by default
Our apps do their work on your machine. We don't ship your files, snapshots, or disk metadata to our servers as part of normal operation.
Security
We build small, focused tools that touch real user data - APFS snapshots, mounted volumes, files on your disk. Earning the trust to do that is the whole job. Here's how we think about it.
01
Our apps do their work on your machine. We don't ship your files, snapshots, or disk metadata to our servers as part of normal operation.
02
We ask for the smallest set of system permissions a feature needs - and explain what each one is for the first time we ask.
03
All macOS builds are code-signed with our Apple Developer ID and notarised by Apple before release. Releases are reproducible from a tagged commit.
04
We don't run third-party SDKs inside our apps for advertising, attribution, or session replay. Updates are checked over HTTPS against our own server.
05
We prefer Apple's frameworks and a small, audited set of open-source libraries. Where we use OSS, we honour and link to the original licences.
06
We're a small team. That means security reports go straight to the people who wrote the code - not a queue.
Every macOS build we ship is signed with our Apple Developer ID certificate and notarised by Apple. Gatekeeper will refuse to run a binary that has been tampered with after we sign it. We never ask users to right-click-open or to disable Gatekeeper.
We use the macOS App Sandbox and Hardened Runtime where the feature set allows it. Apps that perform privileged work (for example, mounting or unmounting volumes, managing APFS snapshots) ship with the minimum entitlements needed and are clearly documented. Where elevated privileges are required, the relevant component runs as a small, audited helper rather than as part of the main UI process.
Our apps operate on your data locally. When an app reads disk metadata, snapshot information, or files, that work happens on your Mac. Contents never leave your machine unless you explicitly tell the app to send them somewhere you control.
We don't run analytics, telemetry, or crash-reporting SDKs inside our apps that collect identifiable user data. If we ever add opt-in diagnostics for a specific feature, we'll spell it out in the app and in the docs - and it will be off by default.
Updates are delivered over HTTPS from our own update endpoint or from the Mac App Store, depending on the product. Update manifests are signed and our update channel verifies signatures before applying anything. We do not ship background services that auto-install code without a user-visible prompt.
We prefer Apple's first-party frameworks over third-party dependencies. When we do use open-source libraries, we pin versions, review changes before upgrading, and attribute them in the app's "About" or licences screen. We monitor advisories for the libraries we ship.
Our website is hosted on Cloudflare Workers. All traffic to scaleninja.com
and our subdomains is served over HTTPS using modern TLS, with HSTS enabled.
Cloudflare provides DDoS protection, a Web Application Firewall, and bot
management on the edge.
Email and form submissions are received through Google Workspace (Gmail, Google Forms). Internal documents and customer correspondence live in Google Drive / Docs / Sheets, with two-factor authentication required on every account that can access them.
Source code lives in GitHub with branch protection on the main branches and signed commits required for releases. Production secrets (signing keys, API tokens, deploy credentials) are stored in encrypted secret managers - never in the repository.
Paid products are sold through third-party payment processors and, where applicable, the Mac App Store. We do not see, store, or process your full card details - they go directly to the processor, who is PCI-DSS compliant. We only receive limited transaction metadata needed to issue receipts and meet our accounting obligations. See our Privacy Policy for more.
If you believe you've found a security issue in any ScaleNinja app, tool, or website, please tell us before sharing it publicly. We treat security reports as a top priority and will work with you to understand, reproduce, and fix the issue.
Email security@scaleninja.com with as much of the following as you can put together:
You can request a PGP key from the same address if you'd like to encrypt your report. For non-security questions, please use support or our contact form instead.
We don't currently run a paid bug-bounty program. Researchers who find genuinely impactful issues may receive a thank-you gift or app licences at our discretion - but the main reward is public credit and a real fix shipped quickly.
The following generally do not qualify as security vulnerabilities. Please don't send reports for these unless they're chained into a real impact:
For security reports: security@scaleninja.com. For everything else, see our contact page.
Last updated: June 17, 2026