Security

Found a security problem? Tell us.

Last updated: August 5, 2026

How to report

Email [email protected] with "Security" in the subject line. Useful things to include: which Liptyper version and macOS version, what an attacker could do, and the steps to reproduce it. A rough report beats no report — send what you have.

Liptyper is a small independent product. There is no bug bounty and no reward program. What there is, is a person who reads the mail.

What we commit to

What counts as good faith

Test against your own Mac and your own copy of Liptyper. Do not access, modify, or destroy other people's data. Do not run denial-of-service, spam, or social-engineering attacks against us or our customers. Give us a reasonable window to fix the issue before publishing — 90 days is the usual expectation, and we will say so if a fix needs longer. If you stay inside those lines, we consider your work authorized.

In scope

Out of scope

What we do not claim

Liptyper has not been independently security-audited or penetration-tested, and it carries no security certification. It is a notarized macOS app built with a hardened runtime, and it does not send your dictation anywhere. That is the whole of the claim.

Bill of materials

We keep a machine-readable list of every open-source component in each release, in CycloneDX format, so a newly disclosed vulnerability can be matched against what actually shipped. Ask at [email protected] and we will send the file for your version.

Updates

Liptyper does not update itself. When a security fix ships we announce it on this page and email customers through the purchase channel, so a new download is a deliberate step you take.

Contact

[email protected]. Company details are on the legal notice.