| Version | Supported |
|---|---|
| 1.0.x | ✅ |
- All downloaded models are verified using SHA256 checksums
- Installation fails if checksum doesn't match
- Protects against corrupted or tampered models
- Homebrew installation requires explicit user confirmation
- Installation script is downloaded to temporary file and can be inspected
- No automatic execution of remote scripts without user review
- All transcription happens locally on your device
- No data is sent to external servers
- Your audio/video files never leave your computer
- Installs only in user directories (
~/Library/Application Support/) - Does not require root/sudo privileges
- No system-wide modifications
- All file paths properly quoted to prevent command injection
- Validation of input files before processing
- Temporary files cleaned up after use
If you discover a security vulnerability in Transcribe App, please report it responsibly:
- DO NOT open a public GitHub issue for security vulnerabilities
- Send an email to: sd.reg01@bk.ru
- Include:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes
- Acknowledgment: Within 48 hours
- Initial Assessment: Within 5 business days
- Fix Timeline: Depends on severity
- Critical: 7 days
- High: 14 days
- Medium: 30 days
- Low: Best effort
- We request that you do not publicly disclose the vulnerability until we've had a reasonable time to fix it
- We will credit you in the security advisory (if you wish)
- We will notify users of security updates through GitHub releases
- The installer relies on Homebrew from brew.sh
- Users should verify they're downloading from the official Homebrew source
- AI model is downloaded from HuggingFace
- While we verify checksums, the source repository could be compromised
- We monitor the upstream repository for any suspicious changes
- Application is not code-signed (requires Apple Developer account)
- Users may see security warnings from macOS
- Users should only download from official GitHub repository
-
Verify Source: Only download from official GitHub repository
https://github.com/PMCulture-pro/transcribe-app -
Check Release Signatures: Verify you're using an official release
-
Review Scripts: Installation scripts are open source - review before running
- Inspect Homebrew Script: Installer shows first 10 lines before execution
- Confirm Each Step: Installation asks for confirmation at critical steps
- Monitor Progress: Watch for any unexpected behavior
-
Verify Checksum: Installation confirms model integrity
-
Check Permissions: Application should only access:
- Your selected audio/video files
- Installation directory
- Temporary files
-
Monitor Activity: No network activity should occur during transcription
- Security updates will be released as soon as possible
- All security fixes will be clearly marked in release notes
- Users will be notified through GitHub release notifications
For security concerns:
- Email: sd.reg01@bk.ru
- GitHub Security Advisories: https://github.com/PMCulture-pro/transcribe-app/security/advisories
For general questions:
- GitHub Issues: https://github.com/PMCulture-pro/transcribe-app/issues
- GitHub Discussions: https://github.com/PMCulture-pro/transcribe-app/discussions
Last Updated: 2025-10-05
Thank you for helping keep Transcribe App secure!