Security fixes are provided for the latest stable release. Users should update to the newest version before reporting an issue that may already be fixed.
We take security seriously. If you discover a security vulnerability, please follow these steps:
- Do not open a public issue on GitHub
- Use GitHub's private vulnerability reporting to submit details
- Include steps to reproduce, if possible
- Allow up to 48 hours for acknowledgment
- We will provide an estimated timeline for the fix
Sorty releases are distributed as pre-built ZIP archives. The app is not signed with an Apple Developer ID certificate or notarized. Sparkle update archives are separately signed with an Ed25519 update key and verified before installation. When installing the app for the first time:
- macOS may show a security warning on first launch
- You need to remove the quarantine attribute manually:
xattr -cr /Applications/Sorty.app - This is common for open source macOS applications without paid developer accounts
- Build from source if you prefer complete control over the build process
Sorty runs within the macOS App Sandbox with the following entitlements:
- User-selected file access (read/write)
- Network access for AI provider APIs
- No system-level access outside the sandbox
- The Learnings Profile: Stored with AES-256 encryption
- Biometric Protection: Touch ID/Face ID required to access learning data
- Organization History: Stored locally, not encrypted (contains file paths and metadata)
- Settings: Stored in standard UserDefaults
When using cloud-based AI providers (OpenAI, Anthropic, etc.):
- File names and metadata are sent for analysis
- File contents are NOT uploaded unless Deep Scan is explicitly enabled
- API keys are stored in the macOS Keychain
- Traffic occurs over HTTPS
For maximum privacy, use local options:
- Ollama: Processes files entirely on your machine
- Apple Foundation Models: On-device processing via Apple Intelligence
- All API calls use HTTPS with TLS 1.2+
- API keys are never logged or transmitted outside AI provider endpoints
- Update checks fetch Sparkle appcasts and release archives from GitHub Releases over HTTPS
- Anonymous product analytics and crash reports are sent to PostHog only after explicit opt-in; file names, paths, contents, prompts, AI responses, and API keys are excluded
- Block Internet Connections disables analytics along with other non-local network access
- Dependencies are pinned in Package.resolved
- GitHub Actions workflows scan for secrets using Gitleaks
- Automated security checks run on every commit
- Release builds are produced by the repository's published GitHub Actions workflows
-
Use Local AI When Possible
- Ollama keeps all processing on your device
- Apple Foundation Models require macOS 15+
-
Secure Your API Keys
- Store keys in the macOS Keychain, not in plain text
- Use environment variables for CLI tools
- Rotate keys periodically
- Never commit keys to version control
-
Review Deep Scan Settings
- Deep Scan uploads file content excerpts
- Only enable for files you are comfortable analyzing remotely
- Disable for sensitive documents
-
Monitor Watched Folders
- Watched folders have persistent file system access
- Remove folders you no longer want monitored
- Review permissions periodically
-
Backup Before Major Operations
- Safe Deletion provides a recovery window
- Consider Time Machine or other backups for important directories
- Test the rollback feature before relying on it
If you notice:
- Unexpected network connections
- Files being accessed without your action
- Unusual API usage patterns
- Potential data leaks
Report via GitHub's private vulnerability reporting immediately with details.
In the event of a security incident:
- We will acknowledge reports within 48 hours
- Affected users will be notified via GitHub releases and the in-app update system
- Fixes will be prioritized based on severity
- Post-incident reports will be published for transparency
- CVE identifiers will be requested when applicable
To minimize network exposure:
// Use local AI only
Settings → AI Provider → Ollama (localhost:11434)
// Disable automatic update checks
Settings → Updates → Manual onlySparkle verifies in-app updates against the Ed25519 public key embedded in Sorty. For a manual download, GitHub publishes a SHA-256 digest in the release asset metadata; you can also calculate the local archive digest:
# Download release
# Check the downloaded archive
shasum -a 256 Sorty-universal.zip
# Or build from source
git clone https://github.com/sorty-organizer/Sorty.git
cd Sorty
make buildSorty integrates with third-party services:
- Sparkle Framework: Verifies signed app updates against Sorty's embedded Ed25519 public key
- Various AI Providers: Each has their own security policies
- GitHub: Hosts releases and update feeds
Review the security policies of your chosen AI provider:
- Security Issues: Use GitHub's private vulnerability reporting
- General Questions: Open a GitHub discussion (not for vulnerabilities)
Last updated: July 2026