# Security

Canonical: https://plottypus.com/security

Last updated: 2026-09-23

> How to report a security problem in plottypus, and what counts as one.

plottypus reads system metrics locally, needs no administrator privileges, and never uses the network. If you find a way to make it crash other processes, signal a process it should not, leak data, or escalate privileges, email \<hello@plottypus.com> with the details and a reproduction. Please do not open a public issue. You will get a reply within 72 hours.

## Checking what you downloaded

Every release tarball has a SHA-256 checksum next to it. The binary is ad-hoc signed, not notarized. See [Install](https://plottypus.com/docs/install#tarball-by-hand) for the commands.
