The Short Version
- Signed and notarized by Apple. Proof is code-signed with a verified Apple Developer ID and notarized by Apple, which means Apple scanned the exact binary you downloaded for malware.
- A real, named developer. Proof is published by Erik Sawaya under Apple Developer Team ID
225KXPVW4C, tied to a legally verified Apple developer account. - Local by default. Your catalog and edits are local by default. Optional publishing uploads selected photographs to services you connect; Shared Library beta sync stores encrypted changes in your chosen storage.
- Clear network purposes. Proof contacts GitHub for update checks and downloads. Optional publishing and Shared Library sync use your chosen services or storage. The app does not include advertising or usage-tracking SDKs.
What Apple’s Notarization Checks
Notarization is Apple's trust mechanism for Mac software distributed outside the Mac App Store. Before release, the Proof binary is uploaded to Apple, checked against a valid paid Apple Developer ID, scanned for malware, and issued a notarization ticket.
Your Mac checks that ticket the first time you open Proof. If the app has been changed after signing, even by a single byte, the signature breaks and macOS refuses to launch it. This is the same mechanism used by many paid, closed-source Mac apps.
Verify It Yourself
You do not have to take our word for it. Open Terminal and run:
spctl -a -t exec -vv /Applications/Proof.app
codesign -dvv /Applications/Proof.app
stapler validate /Applications/Proof.app
The first command should report that Gatekeeper accepts the app from a notarized Developer ID. The second command shows the signing identity and Team ID 225KXPVW4C. The third confirms the notarization ticket is stapled to the app.
What Proof Can Access
Proof runs without the App Store sandbox. That is deliberate: a photo tool needs to read the folders you choose, and Proof uses standard macOS tools already on your system, including sips for image conversion and exiftool if you have it installed, to read camera metadata and handle RAW or HEIF files.
Running unsandboxed means Proof can read files on your disk, like other desktop photo editors. The important question is what Proof actually does with that access.
| Proof does | Proof does not |
|---|---|
| Read the image folders you open | Automatically upload or back up your photo library |
| Write thumbnails and previews to a local cache | Send your catalog to a Proof-hosted service |
| Read camera metadata, including EXIF and film simulation details | Collect analytics, telemetry, or usage tracking |
| Check GitHub for updates and connect to publishing services when requested | Contact advertising networks or usage trackers |
Local Cache Locations
You can inspect or delete Proof's local catalog and thumbnail cache at any time:
- Catalog:
~/Library/Application Support/com.werket.proof/ - Thumbnails:
~/Library/Caches/com.werket.proof/
Updates and Optional Connections
On launch, Proof checks whether a newer version is available by fetching a small public manifest from GitHub:
https://github.com/werket-werk/proof-releases/releases/latest/download/latest.json
This is the standard Tauri auto-updater. Any update offered through that channel is cryptographically signed with a key held by the developer, and Proof verifies the update signature before installing it.
Update checks can contact GitHub at startup, on retry, and when you check manually. Downloading an update also uses GitHub’s asset delivery servers. Connecting a publishing account and publishing selected photos adds requests to that service. Shared Library beta sync can use a cloud-synced folder or a compatible server you configure. Website downloads, email signup, and support forms are described separately in the privacy policy.
Why Proof Is Not Open Source
Proof is an independent product in beta development, and the source code is part of the product's intellectual property. That is the same position as many closed-source Mac apps.
What Proof publishes instead is the trust surface that matters for safety: a verified developer identity, Apple notarization, a signed and tamper-evident update channel, a local-first data model, and commands anyone can run to verify the app on their own Mac.
Questions
If this page does not answer a security or privacy concern, use the support form.