DiskWarren Security Architecture
Storage utilities interact with sensitive personal files. We built DiskWarren with a defense-in-depth safety model: 100% on-device processing, hardcoded OS protection barriers, and reversible Trash routing.
Air-Gapped Indexing
All filesystem traversal, inode inspection, size calculation, and duplicate matching run exclusively in local Mac memory. DiskWarren contains zero network telemetry beacons, zero analytics trackers, and zero cloud synchronization hooks.
Permanent Protected System Paths
Our engine implements hardcoded protection barriers preventing deletion of critical macOS locations: /System, /usr, /bin, /sbin, user keychains, and cryptographically sealed APFS snapshots.
Trash-First Reversibility
By default, DiskWarren recycles candidate files directly to the native macOS Trash (~/.Trash). If you need an item back, simply open Trash in Finder, right-click, and choose "Put Back" to restore it to its exact original directory.
Offline Cryptographic Licensing
License keys are verified mathematically using on-device public-key cryptography (Ed25519). The application does not phone home to activate or validate licenses, ensuring seamless operation in classified, corporate, or offline environments.
Transparency, Consent & Control (TCC)
DiskWarren requests Full Disk Access strictly to index System Data, local snapshots, and hidden developer caches like Xcode DerivedData. DiskWarren never accesses network sockets during scan operations and respects user revocations at all times.