Scope and trust assumptions
Protected assets include device authorization, the exact device identifier, coordinates and history, local paths, process privileges, and the integrity of the native/Python boundary. PinShift never asks for an Apple ID, account token, or another person's location.
The host operating system, signed application bundle, and user account must remain trusted. A local attacker able to replace the installed app or sidecar is outside this model.
Webview and native boundary
The Tauri webview can call only named operations for environment checks, setup repair, authorized-device preparation, start/clear simulation, cancellation, bounded timeouts, demo scenarios in demo builds, and the explicit quit-without-restore choice.
Process and argument safety
- Rust starts one fixed packaged sidecar path.
- Device IDs and coordinates are validated as typed values across Rust and Python boundaries.
- Arguments are passed as an array and never interpolated into a shell command.
- Output is bounded, request IDs must match, and malformed or oversized protocol messages invalidate the worker.
- Only processes owned by PinShift are supervised or stopped.
- A single operation lock prevents incompatible device operations from overlapping.
Recovery and restore
Before sending a set-location request, the native layer writes a private marker that contains only restore-required. It stores no device ID, coordinate, label, or personal path. A confirmed clear removes the marker.
If the app exits unexpectedly, the next launch retains a potentially-active state and offers restore. A failed or unconfirmed clear never becomes a success claim.
Identifiers, storage, and logs
Full device identifiers are not sent to the frontend or stored in favorites, history, or normal logs. Technical output is capped and redacts home/profile paths, UDID-shaped values, coordinate-shaped values, usernames, and temporary paths before IPC.
Release security
A public Mac build must use one Developer ID identity consistently across nested Python components and Tauri, enable hardened runtime, complete Apple notarization, staple the ticket, pass Gatekeeper, and publish an exact SHA-256. The public website refuses to enable a download without those metadata gates.
Network and update boundaries
Updater-enabled builds make one non-blocking check against the fixed HTTPS release feed when PinShift opens. A newer Semantic Version is offered through explicit Update now and Later actions, with a separate manual check in Settings. The updater verifies the Tauri package signature before installation and does not send device identifiers, coordinates, favorites, activity, or analytics.
Installation stays blocked while a location restore may still be required or a device operation is active. The updater atomically acquires the same native gate used by device commands before downloading, then holds it through package installation and restart. Restore-required and asynchronous bridge state are revalidated immediately before installation, so an update cannot silently close the app while the simulated state is unresolved. The pinned device tooling can request a missing Developer Disk Image from its fixed source over TLS; download completion is not treated as a successful mount.
Report a security issue
Do not include full device identifiers, exact private coordinates, pairing records, Apple credentials, or personal paths. Provide the PinShift version, macOS and iOS versions, redacted activity text, and reproducible steps.
Send suspected vulnerabilities through the dedicated private security-reporting form. A free GitHub account is required; the report remains visible only to the reporter and maintainer until disclosure is deliberately coordinated.
For non-sensitive installation or product help, use the separate public support form.