Security
Safe by default, honest about the rest.
What Bagpipper does to protect you, what it sends, and what is still to come. No small print.
Locked down by design
Bagpipper loads only Viremail inside its own windows. Links to anywhere else open in Krodium or in your default browser, never in the window that holds your account.
Every window runs with the operating system sandbox switched on and with context isolation, and web pages have no access to Node or to your files. Developer tools and page reloads are switched off in the released app.
Requests for your location and for USB, Bluetooth, serial, HID and MIDI devices are refused outright. The camera, microphone and screen are used for calls and for the scanner that reads two-step codes, and macOS asks you first.
Krodium is kept apart
Each Krodium tab runs sandboxed in its own session, separate from your Viremail cookies and storage, so a website you visit cannot reach your mail.
When you import from another browser, only bookmarks, history and open tabs come across. Cookies are never imported, and passwords only come in from a file you export yourself, straight into your Vault.
Your data on your Mac
Your sign-in, clipboard history and Krodium data are encrypted with the macOS keychain. Clipboard history never leaves your Mac, skips anything copied from Vault or a password manager, and is wiped when you sign out.
App lock adds a passcode or Touch ID in front of Bagpipper, and can lock it whenever your Mac locks.
No telemetry
Bagpipper does not report what you do. Its logs stay on your Mac. When it checks for a new version it sends the version number it is running, and, like any request on the internet, your IP address reaches our server.
If your company uses Viremail Business and turns on Krodium activity reports, a report reaches the company only after you have read and accepted a notice that says so.
Updates you can check
Every release lists a SHA-256 checksum for each download, published next to the files on the download page. Where an app updates itself, each update is checked against a SHA-512 hash before it is installed.
The Mac build is not yet signed with an Apple Developer ID, so macOS asks you to confirm it the first time you open it, and new versions are installed from the download page. Signing and notarisation are in progress, and this page will say so when they are done.
Reporting a vulnerability
If you believe you have found a security problem in Bagpipper, Viremail or Krodium, please write to [email protected] with "Security" in the subject. Include the steps to reproduce it and what you think the impact is.
We aim to reply within three working days, will keep you updated while we fix it, and credit you if you would like us to. Please give us a reasonable time to fix the problem before you tell anyone else, do not access or change other people’s data, and do not run tests that could harm our service or other users.
For how we handle personal data, read the privacy policy.