Security boundary: StoreCrow limits application access with an operator passcode and auto-lock, restricts local file permissions, and validates backups and portable exports. It does not replace device login security or full-disk encryption.
Recommended operator setup
- Enable FileVault or equivalent full-disk encryption.
- Use a dedicated, non-shared operating-system account.
- Keep verified backups on encrypted removable media and test recovery.
- Install only signed release builds from the approved release channel.
- Do not email unencrypted databases, backups or portable exports.
Dependencies and updates
Release candidates carry a locked dependency inventory and CycloneDX SBOM. The Mac App Store build uses Apple's distribution and update channel. The separate direct-download updater remains disabled until a signed endpoint, signing credentials and release evidence are configured.
Report a vulnerability
Send a concise report to security@storecrow.com. Do not include live tenant data.