Security and IT

Reporting a security problem

If you've found a way to get around something Parallex is meant to keep apart or keep safe, I'd like to hear about it first, privately.

Last updated October 7, 2026.

On this page
  1. How to report
  2. What's covered
  3. Testing
  4. What happens next
  5. On Macs your organization manages

How to report

Write to hello@mandip.dev with "Security" in the subject. Say what you found, the steps to see it happen, the Parallex version and macOS version, and what someone could do with it. A short way to make it happen helps more than a long write-up. Please don't put the details in a public GitHub issue.

The same address is in security.txt.

What's covered

  • The Parallex app, its command-line tool, and the instances and agent workspaces it makes: anything that lets one instance, workspace or run reach another's data, or reach your own beyond what you chose to share.
  • Its updates: anything that could get a Mac to install something that isn't a signed Parallex release.
  • This website and its server at parallex.mandip.dev: licenses and keys, accounts and sign-in, the update feed and downloads.

Not covered: problems in the apps you run inside Parallex (unless Parallex makes them worse), in Stripe, Cloudflare, Resend or GitHub (report those to them), attacks that need someone who already controls your Mac as an administrator, flooding the site with traffic, and tricking people.

Testing

Use your own Mac, your own license or trial, and your own account. Don't look at or change anyone else's data, don't send email to addresses that aren't yours, and stop as soon as you've shown the problem. Good-faith research done this way is welcome, and I won't take action against you for it.

What happens next

Parallex is made by one person, so I'll be honest about timing. I aim to reply within 3 working days, and to tell you whether I can reproduce it within a week. Serious problems are fixed first, usually within 30 days, and the fix ships as a Parallex update; the release notes say what was fixed once it's safe to. I'll keep you posted, and ask before saying anything public about your report.

Please give me time to ship a fix before you publish, up to 90 days from your report. There's no paid bug bounty, but I'm glad to thank you by name in the release notes if you'd like.

On Macs your organization manages

How to deploy Parallex, lock its settings with a configuration profile, and what its copies look like to EDR and Santa (they're re-signed on each Mac and load Parallex's own library) is in Parallex in managed fleets.