FIFTYCAL Home

// SECURITY

Security

Last updated: 2026-04-28

FiftyCAL is built so the highest-value data — your recordings — never leaves your Mac. Cloud surface only handles the minimum needed for accounts, leaderboards, and license activation.

How recordings are stored

Authentication

License keys

Licenses are signed Ed25519 payloads. Your Mac verifies the signature offline against an embedded public key, so the app keeps working when you're offline. Revocation is enforced server-side at activation time.

Transport

Every cloud call is HTTPS (TLS 1.2+). HSTS enforced on fiftycal.app. Cloudflare provides DDoS protection and edge WAF rules.

App distribution

Reporting a vulnerability

Please email security@fiftycal.app with details. We respond within 48 hours and publish a fix timeline. We do not currently run a paid bug bounty but credit researchers in the release notes.