Security

He can see your screen and click in your apps. So here is what keeps that safe.

Here is how your data is protected, which permissions AirBubble asks your Mac for and why, and how the app is checked before it runs.

It says how to report something you have found, and what happens after you do. Where we have nothing to show yet, we say so.

In flight and at rest

Encrypted every time it leaves your Mac.

The app talks only to AirBubble and to the providers that do specific jobs for us, and always over an encrypted connection.

In transit

Everything the app sends is encrypted with TLS. There is no unencrypted fallback and no setting that turns the check off. If a connection cannot be verified, the app refuses it.

At rest on your Mac

Your notes and your conversation history are stored in AirBubble's own folder on your Mac, under your user account, and protected by FileVault if you have it switched on. Screenshots are not kept. Delete a question and its answer and they are removed, and never brought into a later conversation.

At rest on the server

What we store on our servers is encrypted at rest, and only our own service can reach it, over an authenticated connection. The outside services involved are listed on the subprocessors page.

Where your question goes

  1. 1Your MacYou hold the keys and ask. Nothing starts until you do.
  2. 2EncryptedSent over a connection that is checked every time.
  3. 3AirBubbleConfirms it is you, then has our AI provider work out the answer.
Credentials

Your sign-in is kept encrypted on your Mac.

A key saved in a plain file can be read by other apps on the same Mac. AirBubble keeps its sign-in key in an encrypted store instead.

01 Storage

Encrypted on the device

The key that signs the app in to AirBubble is kept in an encrypted store tied to your user account on the Mac. It is never written to a plain file you could open in a text editor.

02 Logs

Kept out of logs

The key is read only when a request needs it. It never appears in a log or a crash report, and our logs are written so they are safe to paste into a support request.

03 Passwords

Nothing of yours to hold

AirBubble never asks for the password to another app or service, and the agent will not type one for you. If a lesson reaches a login screen, it stops and hands the keyboard back.

macOS permissions

What it asks your Mac for, and why.

Each permission is asked for when it is first needed, with the reason on screen. You can turn any of them off in System Settings whenever you like.

01 Capture

Screen Recording

Lets him see your screen when you hold the keys and ask. Without it he cannot see, and he tells you so.

He never looks between questions. Nothing watches your screen on a timer or in the background.

02 Audio

Microphone

Opens while fn is held and closes when you let go. Dictation works the same way.

There is no wake word and nothing listening in the background. The Notetaker is the one exception. It asks before it records, and it stops by itself after eight silent minutes.

03 Controls

Accessibility

Lets him read the app in front of you when you ask, so he can show you the right place. macOS also requires it before AirBubble can notice you holding its keys.

The agent uses it to click and type for you, and only after you say yes to the run.

Two more, only if you use what needs them. When AirBubble types text for you, as dictation does, macOS may ask whether it can control System Events. If you connect your calendar so the Notetaker can spot a meeting, it asks to read your calendar, and the events are read on your Mac. AirBubble does not ask for Full Disk Access, contacts, photos, location or your keychain, and it installs no kernel extension. If a future release needs a permission that is not on this page, we will add it here before that release ships.

What runs on your machine

Signed by us and checked before it runs.

Apple verifies that AirBubble came from us and has not been changed. The app then checks its own parts every time it uses them.

01 Signing

Signed and notarised

The app is signed with our Apple Developer ID and notarised by Apple before release, so macOS can verify it came from us and has not been altered since. A build that fails that check will not open, and you should not force it.

02 Runtime

Hardened runtime

It runs with Apple's hardened runtime switched on, which closes off common ways for another program to tamper with it while it runs.

03 Parts

Checked every time

The parts of AirBubble that work with your screen and your apps are checked against a fingerprint we record when we build them. If one does not match, it does not run.

The agent

The agent does nothing until you say yes.

Nothing gives that yes for you. Switch Agent Mode off and a run that is under way stops, even halfway through a step.

Any setting that skips a confirmation ships switched off. Turning one on is your decision.

Every change to these safeguards is reviewed as a security change and tested against the real code.

  1. 1Agent Mode is switched on
  2. 2You said yes to this specific run
How the code is kept

How the code is looked after, and what we have not done yet.

We keep outside code to a minimum and review changes before they ship. No outside auditor has checked any of it yet.

Little outside code, locked down

The outside libraries we use are locked to exact versions and updated by hand. An update that touches the screen, input or the network gets a closer review.

What runs on your Mac is what we built and signed.

Reviewed before it ships

Any change to how the app sees your screen, clicks for you or talks to our servers is reviewed as a security change. The agent's safeguards are tested against the real code.

Our own keys never go into our source code. If one ever slips in, we treat it as exposed and replace it.

No certification yet

AirBubble holds no SOC 2 report and no ISO certification, and no external penetration test has been commissioned yet. There is no audit under way that we are waiting to announce.

When a report exists, this page will name the firm, the scope and the date.

Coordinated disclosure

Found something? Tell us before you tell the internet.

We would rather hear it from you than read it somewhere else. Report it privately, give us a reasonable window to fix it, and we will keep you in the loop while we do.

How to report

Send it to the security address below. Include what you did, what happened, and what you expected. Add the macOS version and the AirBubble build number, which is in the app under About.

A short proof of concept helps more than a scanner export. If you would rather encrypt the report, say so in the first mail and we will send you a key.

Security contact

Provisional: security@airbubble.io. This mailbox is not live yet. Until it is, use support and mark the message as a security report, and we will move it to a private channel.

Response target

Provisional: acknowledgement within a few business days, a first assessment after that, and progress updates until it is closed. The exact hours are not set yet, and we will not publish a number we cannot hold.

Follow-up

What happens next

  1. 1We confirm we have it, and ask anything we still need.
  2. 2We reproduce it and tell you what we found.
  3. 3We fix it, ship it, and tell you which build carries the fix.
  4. 4We credit you by name if you want it, or keep you anonymous if you do not.

There is no paid bounty programme yet. If that changes, the terms will be on this page.

In scope

  • The current released version of the AirBubble app for Mac, including how it reads the screen, listens for the keys and stores data on your Mac.
  • The AirBubble servers and the API the app talks to.
  • This website and anything served from it.
  • The agent. Anything that makes it click or type without your yes to that run, or while Agent Mode is off.
  • How sign-in details and session data are kept on your Mac.

Out of scope

  • AirBubble appearing in screen recordings and screen shares. That is on purpose.
  • Attacks needing physical access to an unlocked Mac, or an account you already control end to end.
  • Social engineering of our team, our users or our suppliers, and anything involving physical premises.
  • Denial of service, load generation and volumetric testing against our servers.
  • Scanner output with no demonstrated impact, and missing headers or best-practice flags with no exploit path.
  • Issues in third-party services we depend on. Report those to them, and tell us so we can track it.
  • Findings that only reproduce in a modified, repackaged or unsigned build.

Safe harbour (draft)

Research done in good faith should not put you at risk. If you stay inside the scope above, use only your own accounts and test data, avoid touching anyone else's information, avoid degrading the service for other people, and give us a reasonable window before you publish, we will treat your work as authorised and will not pursue legal action over it.

If a report puts you in an unclear position, ask us first and we will answer in writing.

This paragraph is a draft. It has not been reviewed by a lawyer and is not yet a legal commitment. The reviewed version will replace it before launch.

What this page does not claim

No badge yet. Check it for yourself.

Everything above describes how the app behaves and how we work on it. No outside auditor has checked any of it yet.

You can test the visible parts yourself. Hold the keys and watch the microphone indicator come on and go off. Record your screen and see AirBubble in the recording. Turn off Screen Recording in System Settings, ask him something, and he tells you he cannot see.

Last reviewed: pending first release.

Questions we have not answered

If something here is unclear, ask and we will write it down.

We answer security questions the way we answer reports, plainly and in writing. If your answer is missing from this page, it belongs on it.