Security
Last updated 8 October 2026
Cloister runs a component as root and a network filter on your Mac, so security reports come before everything else.
Reporting a vulnerability
Email security@getcloister.app with what you found, how to reproduce it, and your versions of Cloister and macOS. Please do not disclose it publicly until it is fixed.
- We acknowledge your report within 3 business days.
- Within 10 business days we tell you whether we can reproduce it and what we plan to do.
- We aim to fix serious issues within 30 days, sooner if they are being exploited, and we tell you before we publish.
- With your permission, we credit you in the release notes.
We will not take legal action over research done in good faith: on your own Macs, without accessing other people's data, and with reasonable time for us to fix before you disclose.
What counts
In scope: the Cloister app, its background component and network filter, the update feed and downloads, and getcloister.app.
Ways to end a session early are bugs we want to hear about, here or through support. They are not security vulnerabilities unless they also let someone do something they otherwise could not — run code as root, for example. Removing Cloister from your own Mac with administrator access or Recovery mode is a known limit, not a vulnerability: Cloister is a commitment device, not a security boundary against the Mac's own administrator.
Supported versions
Security fixes are made for the current version. A release that fixes a vulnerability is free for everyone whose support period is running — five years from when they first bought their licence — even after their update window has closed (Terms §4.3).
If a vulnerability is exploited
If we learn that a vulnerability in Cloister is being actively exploited, we report it as the EU Cyber Resilience Act requires, and tell affected users in the app's update notes and on this page.