Found a security problem? Tell us.
Last updated: August 5, 2026
How to report
Email [email protected] with "Security" in the subject line. Useful things to include: which Liptyper version and macOS version, what an attacker could do, and the steps to reproduce it. A rough report beats no report — send what you have.
Liptyper is a small independent product. There is no bug bounty and no reward program. What there is, is a person who reads the mail.
What we commit to
- We acknowledge your report within 3 business days.
- We tell you within 10 business days whether we can reproduce it and what we intend to do.
- We keep you updated while we work on a fix, and we tell you when the fix ships.
- We credit you by name or handle when a fix ships, unless you would rather stay anonymous.
- We will not pursue legal action, or ask anyone else to, over good-faith research that follows this page.
What counts as good faith
Test against your own Mac and your own copy of Liptyper. Do not access, modify, or destroy other people's data. Do not run denial-of-service, spam, or social-engineering attacks against us or our customers. Give us a reasonable window to fix the issue before publishing — 90 days is the usual expectation, and we will say so if a fix needs longer. If you stay inside those lines, we consider your work authorized.
In scope
- The Liptyper Mac app and its installer DMG.
- This website, liptyper.com.
- Anything about how the app handles your audio, transcripts, vocabulary, or history on disk.
Out of scope
- Gumroad, Hugging Face, Cloudflare, Apple, and the open-source models and libraries Liptyper uses. Report those to their maintainers; if the issue affects Liptyper users, we still want to hear about it.
- Findings that require an attacker who already has admin access to the Mac.
- Missing hardening that has no demonstrated impact.
What we do not claim
Liptyper has not been independently security-audited or penetration-tested, and it carries no security certification. It is a notarized macOS app built with a hardened runtime, and it does not send your dictation anywhere. That is the whole of the claim.
Bill of materials
We keep a machine-readable list of every open-source component in each release, in CycloneDX format, so a newly disclosed vulnerability can be matched against what actually shipped. Ask at [email protected] and we will send the file for your version.
Updates
Liptyper does not update itself. When a security fix ships we announce it on this page and email customers through the purchase channel, so a new download is a deliberate step you take.
Contact
[email protected]. Company details are on the legal notice.