Security
Thank you for helping keep Outmake and the people who use it safe. If you’ve found a security problem in the Outmake app, outmake.app or Outmake’s measurements server, we’d be grateful to hear about it.
How to tell us
Email hello@outmake.app with “Security” in the subject. Please include:
- what you found, and where;
- the steps to reproduce it, and the Outmake and macOS versions;
- what someone could do with it, as far as you know.
If you’d like to encrypt your report, say so and we’ll arrange it.
What you can expect from us
- We aim to reply within three business days.
- Honest updates while we work on it, and a note when it’s fixed.
- Credit in the release notes, if you’d like it.
We ask that you give us 90 days, or until a fix is released if that’s sooner, before you publish details, so people can update first.
Research in good faith
We won’t pursue legal action against you for security research that:
- stays on your own Mac, your own accounts and data you own;
- avoids harm to other people’s privacy, data and service;
- stops at the point of showing the problem, and tells us promptly.
Please don’t test against other people’s Macs or accounts, run denial-of- service tests against our servers, or use social engineering. Problems in services Outmake connects to, such as Anthropic, OpenAI, Google, Hugging Face or Civitai, belong with those companies.
What we do to keep Outmake safe
- Every release is signed with our Apple Developer ID and notarized by Apple.
- Updates are signed, and Outmake checks the signature before installing one.
- Below Full Access, Claude and OpenCode run their commands inside a macOS sandbox and ChatGPT uses its own. Gemini chats aren’t sandboxed yet.
- Your keys stay in the macOS Keychain. Each agent receives only the key for its own company, and below Full Access an agent’s commands can’t read the Keychain.