Skip to content
← Cloister

Security

Last updated 8 October 2026

Cloister runs a component as root and a network filter on your Mac, so security reports come before everything else.

Reporting a vulnerability

Email security@getcloister.app with what you found, how to reproduce it, and your versions of Cloister and macOS. Please do not disclose it publicly until it is fixed.

  • We acknowledge your report within 3 business days.
  • Within 10 business days we tell you whether we can reproduce it and what we plan to do.
  • We aim to fix serious issues within 30 days, sooner if they are being exploited, and we tell you before we publish.
  • With your permission, we credit you in the release notes.

We will not take legal action over research done in good faith: on your own Macs, without accessing other people's data, and with reasonable time for us to fix before you disclose.

What counts

In scope: the Cloister app, its background component and network filter, the update feed and downloads, and getcloister.app.

Ways to end a session early are bugs we want to hear about, here or through support. They are not security vulnerabilities unless they also let someone do something they otherwise could not — run code as root, for example. Removing Cloister from your own Mac with administrator access or Recovery mode is a known limit, not a vulnerability: Cloister is a commitment device, not a security boundary against the Mac's own administrator.

Supported versions

Security fixes are made for the current version. A release that fixes a vulnerability is free for everyone whose support period is running — five years from when they first bought their licence — even after their update window has closed (Terms §4.3).

If a vulnerability is exploited

If we learn that a vulnerability in Cloister is being actively exploited, we report it as the EU Cyber Resilience Act requires, and tell affected users in the app's update notes and on this page.