Security
Last updated September 24, 2026
The strongest security property Katami has is the one it was designed around: your photographs never leave your Mac, so there is no copy of your library anywhere for anyone to breach. What we do hold — your email address, your license and the Macs it is linked to — is described in the Privacy Policy.
Found a vulnerability? See Reporting a Vulnerability.
The app
- Signed and notarised. Katami is signed with our Apple Developer ID and notarised by Apple, so macOS checks it came from us and has not been modified.
- Sandboxed. Katami runs in the macOS App Sandbox, with Hardened Runtime enabled. It can reach only the folders you give it, and it accepts no incoming network connections.
- Signed updates. Updates are downloaded over HTTPS and each is cryptographically signed; Katami refuses any update that is not signed by us.
- Signed licenses. Your license is a signed token bound to your Mac, checked by the app itself. It is stored in the macOS Keychain, readable only on that Mac.
- Local processing. Every model Katami runs, runs on your Mac. The models it downloads are stored sealed, and checked before they are loaded.
- No analytics, by test. The app contains no analytics or crash-reporting service, and an automated test in its build fails if one is added.
- You see what you send. A problem report shows you its contents before it is sent, with your home folder, email address and user name removed from its logs.
Our service
- No passwords. You sign in with a single-use link that expires after ten minutes, so there is no password of yours for us to leak.
- Secrets stored as hashes. Sign-in links and session tokens are stored only in hashed form, so our database alone cannot be used to sign in as you.
- Short-lived sessions. Sign-ins use short-lived tokens that are rotated as they are used; reusing an old one ends the session.
- Encryption in transit. Every connection uses TLS 1.2 or 1.3 with forward secrecy, and our sites are HTTPS-only (HSTS).
- Minimal exposure. The database is not reachable from the internet. Our services run as unprivileged, minimal containers.
- Verified webhooks. Messages from Paddle and our email provider are signature-checked before we act on them.
- Rate limits on sign-in, email and reports, to blunt abuse.
- Dependency scanning. Our service's dependencies are scanned for known vulnerabilities on every change.
Payments
We never see or store your card details. Payment is handled entirely by Paddle, our Merchant of Record, which is PCI DSS Level 1 certified.
People and access
We are a very small team. Access to production systems is limited to the people who need it, and actions taken in our admin tools are recorded in an audit log.
If something goes wrong
If we ever learn of a breach affecting your personal data, we will tell you without undue delay — what happened, what it affects, and what we are doing — and notify the authorities where the law requires, within 72 hours.