Release integrity
The download page identifies the current version and compatibility. macOS verifies the Developer ID signature and Apple notarization before first launch, while Sparkle verifies signed updates before installing them.
Library boundary
The app stores originals and generated files in local item folders. Search databases and embeddings are local rebuildable caches. Media Mill has no account or remote media-processing service.
Assistant permissions
Connections are off by default. Read access and permission to add or run work are separate grants. The connector asks Media Mill to perform changes; it does not become another writer to Library files.
Report a security issue
Email support@untitledapps.dev with “Media Mill security” in the subject. Describe the affected version, expected boundary and shortest reproduction. Do not send private media, credentials or an unredacted exploit in the first message.