Security

Last updated: July 23, 2026

Build isolation

Builds run on genuine Apple hardware in isolated workspaces. Source files, dependencies, temporary keychains, and signing material are removed from the build workspace after the job finishes.

Credentials and transport

App Store Connect keys are encrypted at rest using envelope encryption. Sensitive request headers are redacted from application logs. Production traffic uses HTTPS, and session cookies are HTTP-only and secure.

Payments

Stripe hosts payment collection and the customer billing portal. Macless stores Stripe customer and subscription identifiers but does not store full card numbers or card security codes. Stripe webhook signatures are verified before billing state is accepted.

Report a security issue

Send a clear description and reproduction steps to support@macless.app. Please do not access other users' data, disrupt the service, or publish an unresolved issue.