A Deskifier app is a hardened desktop shell around a web app. This page explains the rules every app built on Deskifier plays by, whether you’re shipping one or deciding whether to install one.
A traditional desktop app asks you to trust it completely: once installed, it can usually do whatever it likes. A browser earns trust differently: it assumes every page might be malicious and walls it off. Deskifier takes the browser’s side of that argument and keeps it, even inside an installed app.
The web content in a Deskifier app is treated exactly the way a browser treats a stranger’s website. Native power exists behind a fence, the fence is closed by default, and every gate in it was designed by asking what happens if the page on the other side is hostile: a compromised dependency, a malicious ad, a hijacked embed. Design for that day first, and the ordinary days take care of themselves.
Only if its developer deliberately enabled file access, and even then only within everyday folders like Documents and Downloads, or files you personally picked in a native open/save window. Reading, writing, and deleting are separate switches; an app can be able to read without being able to change anything.
No. Embedded third-party content (login screens, payment pages, external sites) never receives native capabilities, even the ones the app itself was granted. Requests from that content are refused outright.
Yes. Deskifier apps are built on the same engine that powers Chrome, and web content runs with the same process sandbox and isolation. The difference is that a Deskifier app can additionally offer specific native features, each one deliberately enabled by its developer and individually guarded at runtime.
No. Hardware and system-level permissions are owned by your operating system. An app built with Deskifier has to ask through the OS’s own prompts, exactly like any other app, and your answer is enforced by the OS, not by us.
Installers and updates are code-signed, so your operating system verifies the publisher before anything runs. Updates are delivered over encrypted connections from the app’s own release channel; there is no mechanism for a third party to inject a different build into that path.
The installer should be signed by the publisher you expect; your OS shows this before it runs. Beyond that, the app can only use the capabilities its developer enabled, everything sensitive stays behind the guarantees on this page, and hardware access always goes through your OS’s own prompts. If something seems off, contact the app’s developer, or reach us directly.
Email hello@deskifier.com with the details. Security reports go to the top of the queue, and we would far rather hear something twice than not at all.
This page is written for your users as much as for you. When a customer or an IT team asks how your desktop app behaves, send them here: deskifier.com/security. And if you want the badge to link from, it’s on the brand page.