Security

Security

Security

Last updated: August 6, 2026

Architecture

Architecture

FlowDeck is a native Swift binary that runs entirely on your Mac. There is no cloud component, no remote build service, and no intermediary between your code and Apple’s toolchain.

All builds, tests, and simulator operations execute locally through Apple’s developer toolchain

Source code, project files, build artifacts, and logs never leave your machine

No remote build service, source-code upload, or crash reporter is embedded in the product

Network Activity

FlowDeck makes these product network requests:

FlowDeck makes these product network requests:

License validation, On activation (flowdeck license activate), a request is made to Lemon Squeezy’s API to validate your license key and register a machine identifier.

Update check, After a command completes, FlowDeck checks for available updates in the background. No user data is sent, it fetches a version file from the update server.

macOS app analytics, The FlowDeck Studio macOS app sends PostHog product analytics using a salted one-way hash as the distinct ID.

No source code, project files, build logs, compiler output, terminal output, repository names, branch names, file paths, or crash reports are transmitted.

No source code, project files, build logs, compiler output, terminal output, repository names, branch names, file paths, or crash reports are transmitted.

Telemetry Boundaries

The FlowDeck CLI ships with zero product telemetry. The FlowDeck Studio macOS app uses PostHog with a strict product-analytics boundary. We do not collect:

The FlowDeck CLI ships with zero product telemetry. The FlowDeck Studio macOS app uses PostHog with a strict product-analytics boundary. We do not collect:

Source code or project files

Build logs, compiler output, or terminal output

Project names, schemes, or targets

File paths or directory structures

Names, email addresses, license keys, license IDs, or license statuses through PostHog

Crash reports or stack traces

Code Signing

Both FlowDeck CLI and FlowDeck studio binaries are signed and notarized by Apple.

Both FlowDeck CLI and FlowDeck studio binaries are signed and notarized by Apple.

Supply Chain

FlowDeck is written in Swift and depends only on Apple system frameworks and Swift Package Manager packages. There are no Node.js dependencies, no npm packages, and no interpreted runtime in the production binary.

FlowDeck is written in Swift and depends only on Apple system frameworks and Swift Package Manager packages. There are no Node.js dependencies, no npm packages, and no interpreted runtime in the production binary.

AI Agent Integration

When used with AI coding agents (Claude Code, Codex, Cursor), FlowDeck acts as a local tool. The agent invokes FlowDeck commands through the shell. FlowDeck does not communicate with AI providers, does not send code or build output to any remote service, and does not modify the agent’s behavior.

When used with AI coding agents (Claude Code, Codex, Cursor), FlowDeck acts as a local tool. The agent invokes FlowDeck commands through the shell. FlowDeck does not communicate with AI providers, does not send code or build output to any remote service, and does not modify the agent’s behavior.

All data flowing between the agent and FlowDeck stays on your machine. What the agent does with that data is governed by the agent’s own privacy policy, not ours.

All data flowing between the agent and FlowDeck stays on your machine. What the agent does with that data is governed by the agent’s own privacy policy, not ours.

License Data

License management is handled by Lemon Squeezy. When you activate a license, the following is sent to their API:

License management is handled by Lemon Squeezy. When you activate a license, the following is sent to their API:

Your license key

A machine fingerprint (to enforce license activation limits)

No other data is transmitted. See our Privacy Policy for details on what personal information we collect at purchase.

No other data is transmitted. See our Privacy Policy for details on what personal information we collect at purchase.

Vulnerability Reporting

If you discover a security vulnerability in FlowDeck, please report it to:

If you discover a security vulnerability in FlowDeck, please report it to:

security@flowdeck.studio

security@flowdeck.studio

We take all reports seriously and will respond within 48 hours. Please do not disclose vulnerabilities publicly until we’ve had a chance to address them.

We take all reports seriously and will respond within 48 hours. Please do not disclose vulnerabilities publicly until we’ve had a chance to address them.

Contact

For security questions or concerns:

For security questions or concerns:

security@flowdeck.studio

security@flowdeck.studio