← Notes

The Mac App Store sandbox, and what it stops an app doing

Sandboxing is the strongest privacy guarantee available on a Mac, because it is enforced by the system rather than promised by a developer. Here is what it actually prevents, and what it does not.

Every app distributed through the Mac App Store must run in a sandbox. Most people know this as a vague reassurance. It is considerably more specific than that, and it is the only privacy claim on a Mac that does not depend on trusting anybody.

What a sandbox is

A set of restrictions the operating system enforces on a running process. The app declares, in advance, which capabilities it needs — these are entitlements — and the system permits those and blocks everything else.

The crucial property: this is not a policy the app agrees to follow. It is a boundary the kernel enforces. An app without the network entitlement does not "choose not to" make network connections; the attempt fails. Malicious code, a compromised dependency, a bug — none of it matters, because the capability is absent.

That is qualitatively different from a privacy policy, which is a statement of intent.

What it blocks by default

A sandboxed app starts with almost nothing and must ask for each capability:

  • Filesystem. It can read and write inside its own container and nowhere else. It cannot read your Documents folder, your Desktop, other apps' data, or system files — unless you pick a file, at which point the system grants access to that file specifically. This is why sandboxed apps use the standard open dialog rather than browsing your disk themselves.
  • Network. Separate entitlements for outgoing and incoming connections. No entitlement, no connections at all.
  • Hardware. Camera, microphone, USB, Bluetooth, printing — each separately declared.
  • Other apps. It cannot read another application's memory or send it events without explicit permission.
  • Your personal data. Contacts, Calendar, Photos, Location — each a separate entitlement, each triggering a prompt.

Why "no network entitlement" is the strongest claim

If an app has no outgoing network entitlement, it cannot transmit your data. Not "does not". Cannot.

There is no configuration that turns it on later, no update that silently adds it without re-review, no bug that works around it. The system refuses the connection.

When an app page says "your files never leave your Mac", this is the version of that sentence with something behind it. Everything else is a promise.

Checking for yourself

Terminal, one command:

codesign -d --entitlements - /Applications/Something.app

You get a list. Things to look for:

  • com.apple.security.app-sandbox — is it sandboxed at all?
  • com.apple.security.network.client — can it make outgoing connections?
  • com.apple.security.files.user-selected.read-write — normal, means it works with files you choose.
  • com.apple.security.files.all or broad temporary exceptions — worth a second look.

What it does not protect against

Sandboxing is strong and it is not everything, and pretending otherwise is the same overclaiming this article is arguing against.

It does not stop an app misusing what you gave it. Grant Contacts access and the app has your contacts. If it also has network access, the sandbox has no opinion about combining them.

It does not apply outside the App Store. Apps distributed directly can be sandboxed and many good ones are, but it is not required. Notarisation — which most direct downloads have — is a malware scan, not a capability restriction. They are different things and are frequently confused.

It does not cover permissions you grant at runtime. Full Disk Access, Accessibility, Input Monitoring and Screen Recording are granted by you in System Settings and sit alongside the sandbox rather than inside it.

It says nothing about quality or honesty. A sandboxed app can still be badly written or misleading. It just cannot exfiltrate data it was never allowed to reach.

The trade-off, honestly

Sandboxing costs capability. It is why some excellent Mac utilities are not on the App Store — a tool that genuinely needs to operate across your whole filesystem, or hook into the system deeply, cannot do its job inside the restrictions.

So "not sandboxed" is not a red flag by itself. Plenty of good software lives outside for legitimate reasons. It does mean the guarantee is absent and you are back to trusting the developer, which is a reasonable thing to do knowingly and a bad thing to do by default.

Where we sit

Our Mac apps are distributed through the Mac App Store and are therefore sandboxed. The one worth calling out specifically:

RenameDeck has no network entitlement at all. Names and metadata are processed on your Mac because the app is structurally incapable of doing anything else. That is the claim in this article with the system behind it rather than us.

The others follow the same pattern within what their jobs require: Ziploom has no accounts, analytics, telemetry or network features; ClackSmith requests neither Input Monitoring nor Accessibility; Compact Contacts reads the contacts macOS already has with no developer backend and no app account; Miyu Paint and Garfi do their work on your device.

You do not have to take our word for any of it. The command above works on anything in your Applications folder, including ours.

Keep reading