Security

Last updated: 8 October 2026

In short

Found a security problem in Hushtop, this website or our license server? Email [email protected]. We won’t take legal action over research done in good faith under this page.

On this page
  1. How to report
  2. What to include
  3. What happens next
  4. Safe harbor
  5. In scope
  6. Out of scope
  7. How we protect Hushtop

How to report#

Email [email protected]. Please don’t post the problem publicly, in our Discord or anywhere else, until we’ve fixed it.

Our contact details are also in /.well-known/security.txt.

What to include#

  • What’s affected: the Hushtop and macOS versions, or the URL.
  • The steps to reproduce it, with a proof of concept if you have one.
  • What an attacker could do with it.
  • How to reach you, and whether you’d like to be credited.

What happens next#

  • We read every report and reply as soon as we can.
  • We confirm the problem, tell you our plan and keep you posted until it’s fixed.
  • We ask you to keep it private until a fix ships, or for 90 days, whichever comes first.
  • With your permission, we credit you when we publish the fix.

Safe harbor#

If you research in good faith and follow this page, we consider your research authorized, we won’t take legal action against you, and we won’t ask anyone else to. Good faith means you:

  • only test against your own copy of Hushtop, your own license and your own data
  • stop and tell us as soon as you reach anyone else’s data, and don’t keep or share it
  • don’t degrade our services, destroy data or try to break in by volume
  • give us reasonable time to fix the problem before you talk about it

In scope#

  • The latest version of the Hushtop app
  • hushtop.app, this website
  • license.hushtop.app, our license and update server

Out of scope#

  • Denial of service, load testing and spam.
  • Social engineering, phishing and physical attacks.
  • Services run by others, such as Paddle, Cloudflare, Resend, GitHub or Discord. Please report those to them.
  • Reports from automated scanners, or missing headers and best practices, without a way to exploit them.
  • Problems that need a Mac that’s already compromised, or admin access to it.
  • Ways around the licensing on a Mac you control.

How we protect Hushtop#

The website. Every page has a strict Content Security Policy: scripts run only with a fresh per-request nonce, and the only outside script allowed is Paddle’s checkout. There’s no analytics and no tracking. Your browser never calls the license server. Restoring a purchase and showing your key after checkout go through our website server, which calls the license server with its own secret key. The license server allows no cross-site requests at all.

The license server. It runs on Cloudflare Workers, D1 and R2. License keys are stored as a hash for lookup and encrypted with AES-256-GCM for re-sending. Purchase emails are stored only as a hash. License and website requests are rate limited and must be small JSON, and our logs never contain license keys or email addresses. The owner’s dashboard sits behind Cloudflare Access.

The app. Hushtop is signed with our Developer ID, notarized by Apple and runs with the hardened runtime. Licenses are signed tokens tied to one Mac. Updates come through Sparkle, over HTTPS, and each one is signed with our EdDSA key: Hushtop installs an update only if its signature checks out.