Privacy & security
What Wardlume can and can't access, how to verify that it can't reach the internet, and how updates work.
Settings → Privacy & security shows what Wardlume can reach. It reads these facts live from the app itself. You can also open it from the Privacy › button at the top of Overview.
| Internet access | Blocked by macOS. Wardlume runs in Apple’s App Sandbox with no network entitlement, so macOS refuses every connection it tries. |
| Screen capture | Only while warded. It draws your live desktop behind the glass, and is off the rest of the time. |
| Recordings saved | None. Frames go straight to the GPU and are never written to disk. |
| Camera | Off unless you turn on Intruder photo. Then only on a failed unlock, with photos kept on this Mac. |
Verify it yourself
Run this in Terminal:
codesign -d --entitlements - /Applications/Wardlume.app
You’ll see com.apple.security.app-sandbox, com.apple.security.screen-recording, and com.apple.security.device.camera (so Intruder photo can be turned on; macOS still asks you first), and no com.apple.security.network.client or network.server. Without those, the app can’t open a connection.
A network monitor such as LuLu (free) or Little Snitch confirms this in practice: Wardlume itself never connects.
What goes online: only the updater
Updates are the one exception, and they don’t run inside Wardlume:
- The open-source Sparkle updater’s downloader runs in its own sandbox, with network access only.
- It fetches the update feed from
wardlume.github.ioand, when you install, the update from Wardlume’s public GitHub releases. - Every update is signed and checked before it’s installed.
- Nothing about you or your Mac is sent.
Little Snitch shows Wardlume’s built-in network policy, which explains each of these connections.
Manage it in Settings → Advanced → Updates (see Update & uninstall).
Something unclear or out of date? Tell us in Discussions.