Tasks signed, gated, and receipted end to end.
A Common Compute task crosses a lot of trust boundaries — your code, our coordinator, someone else's Mac. Task assignments are signed, every input is vetted at a single chokepoint, and the provider app ships hardened, signed, and notarized. Here is exactly how — including the parts we haven’t built yet.
Found something? Tell us.
Email security@commoncompute.ai with a description and steps to reproduce. We acknowledge within 7 calendar days and aim to ship a fix within 30 days for high-severity issues.
We don't run a paid bounty yet, but we publish a researcher hall of fame for valid reports. Good-faith research is welcome — don't access another user's data, don't degrade the service for others, and give us 90 days before publishing.
Coordinated disclosure policy in full: SECURITY.md
Who else touches your data.
We'd rather be upfront than fake a certification.
Questions we didn't answer here?
We answer security questionnaires by hand. Get in touch and we'll route to whoever owns the answer.