Tasks signed, sandboxed, and exportable as audit trail.
A Common Compute task crosses a lot of trust boundaries — your code, our coordinator, someone else's Mac. Every hop is signed, every input is whitelisted, and the binary that runs your work is signed by us and notarized by Apple. Here is exactly how.
Found something? Tell us.
Email [email protected] with a description and steps to reproduce. We acknowledge within 7 calendar days and aim to ship a fix within 30 days for high-severity issues.
We don't run a paid bounty yet, but we publish a researcher hall of fame for valid reports. Good-faith research is welcome — don't access another user's data, don't degrade the service for others, and give us 90 days before publishing.
Coordinated disclosure policy in full: SECURITY.md
Who else touches your data.
We'd rather be upfront than fake a certification.
Questions we didn't answer here?
We answer security questionnaires by hand. Get in touch and we'll route to whoever owns the answer.