Trust & security

Built as if every page were hostile

A Deskifier app is a hardened desktop shell around a web app. This page explains the rules every app built on Deskifier plays by, whether you’re shipping one or deciding whether to install one.

  • Chromium sandbox
  • Powered by Electron
  • Apple notarized
  • Microsoft signed
  • SHA-512 verified updates
  • AES-256 encrypted
  • PCI DSS via Stripe
Our approach

Start from the worst case

A traditional desktop app asks you to trust it completely: once installed, it can usually do whatever it likes. A browser earns trust differently: it assumes every page might be malicious and walls it off. Deskifier takes the browser’s side of that argument and keeps it, even inside an installed app.

The web content in a Deskifier app is treated exactly the way a browser treats a stranger’s website. Native power exists behind a fence, the fence is closed by default, and every gate in it was designed by asking what happens if the page on the other side is hostile: a compromised dependency, a malicious ad, a hijacked embed. Design for that day first, and the ordinary days take care of themselves.

The rules every app plays by

Hostile by default
Web content inside a Deskifier app runs in the same sandbox a modern browser uses, and we treat every page as if it were compromised. Page code never touches the machine directly.
Every power is opt-in
Native capabilities ship switched off. A developer enables each one individually, so an app that never asked for file access simply does not contain a way to use it.
Files stay fenced
File access is granted per operation: reading, writing, and deleting are separate switches, each confined to everyday folders like Documents and Downloads. Reaching anything beyond the fence requires the person using the app to pick that file or folder themselves, in a native window only they control.
Strangers get nothing
Third-party pages shown inside an app (a login screen, a payment form, an embedded site) never receive native powers, not even the ones the app itself has. A second, independent check refuses them if they ask anyway.
The OS keeps the final say
Cameras, microphones, screen recording, and notifications still go through the operating system’s own permission prompts. Deskifier cannot grant those on an app’s behalf, and doesn’t try.
Signed and accountable
Every build is code-signed: notarized by Apple on macOS, trusted-signed on Windows. Updates arrive over encrypted connections from the app’s own release channel. What runs tomorrow is as accountable as what was installed today.

The standards underneath

  • Chromium sandboxDeskifier apps run every page inside the same sandbox Google engineered to protect Chrome’s billions of users. Web content is walled off from the operating system at the process level, so even a compromised page can’t reach the machine underneath.
  • Powered by ElectronDeskifier is built on Electron, the open-source framework started at GitHub and now governed by the OpenJS Foundation. It’s the same foundation trusted by VS Code, Slack, Discord and Figma, and it’s hardened by one of the largest security communities in open source.
  • Apple notarizedEvery Deskifier macOS build is submitted to Apple and scanned for malicious code before it can ship. Builds are signed with a Developer ID, run under Apple’s Hardened Runtime, and carry a notarization ticket macOS checks on every launch.
  • Microsoft Trusted SigningEvery Windows installer is signed through Microsoft’s Azure Trusted Signing, which ties it to a verified publisher identity. Windows can confirm who built the app and that not a single byte has changed since.
  • Verified updatesUpdates travel over encrypted TLS connections, and every download is checked against a SHA-512 checksum before it’s installed.
  • Encrypted at restAccount data is encrypted with AES-256, the standard trusted by banks and governments, whenever it’s stored, and protected by TLS whenever it moves.
  • Stripe PCI DSS Level 1Payments are processed by Stripe, certified to PCI DSS Level 1, the highest level of security certification in the payments industry. Card details go straight to Stripe and never touch our servers.

Frequently asked questions

Only if its developer deliberately enabled file access, and even then only within everyday folders like Documents and Downloads, or files you personally picked in a native open/save window. Reading, writing, and deleting are separate switches; an app can be able to read without being able to change anything.

No. Embedded third-party content (login screens, payment pages, external sites) never receives native capabilities, even the ones the app itself was granted. Requests from that content are refused outright.

Yes. Deskifier apps are built on the same engine that powers Chrome, and web content runs with the same process sandbox and isolation. The difference is that a Deskifier app can additionally offer specific native features, each one deliberately enabled by its developer and individually guarded at runtime.

No. Hardware and system-level permissions are owned by your operating system. An app built with Deskifier has to ask through the OS’s own prompts, exactly like any other app, and your answer is enforced by the OS, not by us.

Installers and updates are code-signed, so your operating system verifies the publisher before anything runs. Updates are delivered over encrypted connections from the app’s own release channel; there is no mechanism for a third party to inject a different build into that path.

The installer should be signed by the publisher you expect; your OS shows this before it runs. Beyond that, the app can only use the capabilities its developer enabled, everything sensitive stays behind the guarantees on this page, and hardware access always goes through your OS’s own prompts. If something seems off, contact the app’s developer, or reach us directly.

Email hello@deskifier.com with the details. Security reports go to the top of the queue, and we would far rather hear something twice than not at all.

Shipping with Deskifier?

This page is written for your users as much as for you. When a customer or an IT team asks how your desktop app behaves, send them here: deskifier.com/security. And if you want the badge to link from, it’s on the brand page.