Welcome back

Opening shared build

Preparing your Mach workspace…

Preparing your secure download…

SECURITY & TRUST

Security built around the mobile release boundary

Mach handles sensitive signing material and application delivery records. This page explains the controls visible to customers, the limits of connected applications, and the safest way to report a concern.
Encrypted storage
Managed secrets and signing credentials are encrypted at rest and made available only to the workflow that requires them.
Expiring artifact access
Artifact downloads use time-limited access rather than permanent public storage URLs.
Scoped access
Authentication, project roles, and explicit permissions limit which users and connected applications can see each resource.
01

Signing credentials and project secrets

Certificates, provisioning profiles, keystores, service credentials, and project secrets remain outside normal source control and dashboard output. They are decrypted only when an authorized workflow requires them.
Sensitive values are not displayed in ordinary build logs.
Project permissions govern credential and secret management.
Support will never ask you to email passwords, private keys, or secret values.
02

Build runners and artifacts

Build execution is isolated from the public dashboard. Source and credentials are used to perform the requested build, while resulting artifacts are delivered through controlled, expiring access and retained according to the product retention window.
03

Accounts, roles, and connected applications

Short-lived authenticated sessions protect API requests. Project roles control workspace access. Mach MCP connections are explicitly approved and read-only: they cannot publish builds, change projects, read passwords or personal access tokens, or retrieve project secrets through the connected-app interface.
04

Responsible disclosure

If you believe you found a security issue, send a concise report with the affected URL, reproducible steps, impact, and any non-sensitive evidence. Do not access another customer’s data, run destructive tests, or disclose a potential issue publicly before we can investigate.
Use the monitored address published in our security.txt file.
Remove passwords, tokens, signing keys, and private customer data from evidence.
We will acknowledge actionable reports and coordinate remediation communication in good faith.
05

Transparency and scope

Security evolves with the service. Product documentation and this page describe currently published controls; Mach does not claim an audit or compliance certification unless that certification is explicitly named and verifiable here.
Report a security concern
Contact the monitored Mach support address with a responsible disclosure report. Please do not include credentials or secret values.
Email security report
Mach
Cloud builds, secure signing, testing, and release delivery for React Native, Flutter, and Expo React Native teams.
Built and operated by Radhya Softlabs · support@getmach.dev
© 2026 Radhya Softlabs. All rights reserved.