Security
Trust layers
- Tailscale account (travel): who can reach your Mac on the private mesh.
- Pair token: what Porter allows after connect. Exact match required.
- Folder allowlists: only shared paths may be listed or copied.
- Secret and dangerous path blocks: .env, keys, keychains, cookies, full Chrome profiles blocked by default.
Settings, Travel Ready, and tunnel controls stay on localhost. Remote file APIs require the pair token. Confirm writes are on by default. Activity log shows what happened.
Honest residual risk
Anything inside an allowlisted folder can be read by a connected AI or peer with your token. A stolen pair token on your mesh is dangerous. A compromised Mac can abuse a running agent. Porter keeps power narrow and visible. It does not claim zero risk.
Gatekeeper / notarization
Porter is not Apple-notarized in current releases. macOS may warn on first open. That is Gatekeeper distribution policy for unidentified developers, not a verdict that Porter is malware. Install to Applications, then right-click → Open, or use Privacy and Security → Open Anyway. Download only from official GitHub Releases.
Full write-up: SECURITY.md