Cette page n’existe pour l’instant qu’en anglais. La version française suivra.
Security
Checked against the code on 7 October 2026.
Klar reads your mail, so what it claims should be checkable. Here is what each Klar product is allowed to do and how to check it on your own machine. Then what nobody has checked yet, and where to report a problem.
In short
- The free Mac app and its Mail extension hold no network permission. macOS refuses any connection they try to open.
- Klar Plus holds the network permission. It uses it for a licence check, model updates and a version check, and for two features that stay off until you turn them on.
- Klar for Messages sorts texts on the iPhone. An optional cloud check, off by default, lets iOS send texts the model is unsure about to klar.im.
- No outside firm has audited Klar. What you can check yourself is below.
- Report a vulnerability to security@klar.im.
Klar, the free Mail extension
The free app comes from the Mac App Store, so Apple reviewed it and macOS runs it in the App Sandbox. A sandboxed app can use only the capabilities it declares, and the declarations are sealed into its code signature. Change one and the app no longer launches.
The app and its extension declare exactly this:
- App Sandbox, on both.
- An App Group, a folder only Klar’s own apps can open. The model and the local classification database live there.
- Contacts, on the app only, so mail from people you know is never filtered. macOS asks you first, and the addresses stay in a local database.
They do not declare the network, and they do not declare Apple Events, the permission to control another app such as Mail or Safari. So neither can open a connection of its own, and neither can make another app send something for it.
The extension does nothing until you enable it in Mail, under Settings, Extensions. Nothing else in the app starts by itself: no login item, no launch agent, no background service. When you send us an Email report, Klar opens a draft in your own mail app, and nothing leaves until you press Send.
Check it yourself
Open Terminal once Klar is installed. You do not need to open Klar first, and nothing here changes your Mac.
APP="/Applications/Klar.app"
EXT="$APP/Contents/PlugIns/KlarMailExtension.appex"
# 1. Who signed it
codesign -dv --verbose=4 "$APP" 2>&1 | grep -E 'TeamIdentifier|Authority='
# expect: TeamIdentifier=437587CCNF
# 2. What the app and the extension are allowed to do
codesign -d --entitlements - --xml "$APP" | plutil -p -
codesign -d --entitlements - --xml "$EXT" | plutil -p -
# expect: app-sandbox and application-groups on both,
# personal-information.addressbook on the app only,
# and no line with "network" or "apple-events" in either
# 3. What can run: one Mail extension, nothing that starts by itself
find "$APP/Contents" -name "*.appex" -o -path "*XPCServices*" -o -path "*LoginItems*" -o -path "*LaunchAgents*"
# expect: one line, KlarMailExtension.appexIf a line does not match, delete the app and write to us. The check holds for the version you checked: an update is a new bundle that could declare new permissions, so run it again after one.
The same commands work on any Mac app. How to check what a Mac app is allowed to do explains what each line means, and what the App Store, TestFlight and notarization each check.
Klar Plus
Klar Plus is a separate paid app, in development, sold from klar.im as a notarized download rather than through the App Store. It runs in the App Sandbox too, and it declares more, because it does more:
- The network. Three uses always happen: a licence check with klar.im, model updates from our download server, and a version check against a signed feed on klar.im. None of the three carries your mail.
- Apple Events to Mail. Plus reads and moves your messages by asking Mail. macOS shows you an Automation prompt the first time, and you can withdraw it in System Settings, under Privacy & Security, Automation.
- Files you choose, read only, when you drop a message on Plus.
- Two system lookups that Sparkle, the updater, needs to install an update from inside the sandbox.
Two more uses of the network stay off until you turn them on in Settings:
- Data contribution sends hashed numeric features from mail you confirm as spam. No message text, address or subject. Turning it off deletes what is still queued and asks the server to delete what it has not yet aggregated.
- Second opinion sends a message Klar is unsure about to klar.im. The server passes a trimmed copy to TypeSafe’s Jev model, with your name, email addresses and phone numbers removed, and keeps only the answer. Plus asks for your consent before turning it on.
For Plus, the permission check proves less. An app that can reach the network and read your mail could send your mail. What stands between the two is our code and this list. To see it for yourself, watch its connections with an outbound firewall such as LuLu or Little Snitch.
codesign -d --entitlements - --xml "/Applications/KlarPlus.app" | plutil -p -
# expect: network.client, apple-events with com.apple.mail,
# files.user-selected.read-only, and the two mach-lookup names Sparkle usesKlar for Messages
Klar for Messages is in beta on TestFlight. Its filter is an iOS Message Filter extension: iOS hands it a text from an unknown sender, and it answers junk, transaction, promotion or allow. The model runs on the phone, and the extension has no network access.
The app offers a cloud check, off by default. If you turn it on, iOS itself, not the app, sends the sender and the text of a message the model is unsure about to klar.im. The server keeps a keyed hash of the sender and a similarity hash of the text, never the number or the text. Each record expires after 30 days. The details are in the privacy policy.
Klar Pro, on your own server
Klar Pro is the same engine as a milter that runs on your mail server, for Postfix and Stalwart. Its source is public under the AGPLv3 at github.com/klar-im/engine, so it is the one Klar product you can read line by line.
It scores each message inside its own process and makes no network call per message. The model is downloaded once, at install, and every file is checked against the SHA-256 in its manifest. Its health and metrics endpoints have no authentication, so the daemon refuses to listen on every interface unless you set health_allow_public.
What nobody has checked yet
No independent firm has audited Klar: not the apps, not the engine, not this site. This page will say so until one has, and will then name the firm and what it covered.
What does exist: Apple reviews each App Store build, and TestFlight builds with a lighter review. Notarization means Apple scanned Klar Plus for known malware and knows who signed it. It is not a review of what the app does. The engine’s source is public.
The permission check has limits too. It proves an app cannot open a connection of its own. It does not stop an app from opening a link in your browser when you click one, or from putting text on the clipboard. Both need the app open in front of you. To rule them out as well, run Klar with Wi-Fi off or behind an outbound firewall.
Report a vulnerability
Write to security@klar.im. A person reads it. Say what you found, how to reproduce it, and which version: the version shown in the app’s window, klar-milterd --version, or the image tag.
Klar is built by one person, so these are goals, not guarantees: an acknowledgement within three working days, and a fix or a reasoned answer within thirty. We credit reporters in the release notes unless you ask us not to. Please do not open a public issue for a vulnerability.
In scope: the Mac apps, Klar for Messages, the engine and the milter (see the engine’s SECURITY.md), and klar.im. A spam message that gets through is not a vulnerability: forward it to spam@klar.im. A way to make every spam get through is one.
The same contact, for tools that look for it: /.well-known/security.txt.