Security
Where credentials live
On the Mac
Passwords, key passphrases, AI provider keys and the license key are stored in the macOS Keychain. The connection list on disk holds no passwords, and an SSH key stays a file on disk.
On iPhone and iPad
Passwords and pasted SSH keys are stored in the Keychain.
iCloud Sync
iCloud Sync is off until you turn it on. Records go to a private database in your own iCloud account, which TablePro cannot read, and carry no passwords. Passwords sync only if you also turn on Passwords on the Mac or Sync Passwords on iPhone and iPad, and then through iCloud Keychain.
What TablePro receives
The queries you run, their results and your passwords are not sent to TablePro. The exception is a Team Library you choose to publish to: it receives connection settings and saved queries, never passwords.
Limits worth knowing
- On the Mac, password sync also carries AI provider keys and the license key.
- A password source such as 1Password or a shell command runs a program on your Mac each time you connect.
What leaves your device
To your servers and providers
Queries and results travel between the app and your own database servers, never through TablePro. AI requests go straight to the provider you add.
To TablePro
With no license activated, the only request the Mac app makes to TablePro is a daily usage report, on by default and switchable in Settings. On iPhone and iPad, nothing goes to TablePro unless you turn on Share Usage Data. A report never carries hostnames, usernames, passwords, queries or rows, and neither app contains a crash reporter or a third-party analytics library.
Limits worth knowing
- The Mac app sends its first usage report without asking, and our server stores the IP address of every report and license check.
How the apps reach you
Signed and notarized
Mac builds are signed with a Developer ID, use the Hardened Runtime and are notarized by Apple. The disk images are on GitHub Releases, each with a SHA-256 checksum. The Homebrew cask downloads the same image and checks its SHA-256.
Updates
The Mac app updates through Sparkle and checks each update’s EdDSA signature against the public key inside the app before installing it. That check has no off switch. Automatic updates do, in Settings or in a configuration profile.
Driver plugins
Drivers that do not come with the Mac app download from GitHub. Each must match the SHA-256 in the plugin registry and carry a valid code signature: TablePro’s own, or another developer’s Developer ID once you agree to trust that developer by name.
iPhone and iPad
The iPhone and iPad app is on the App Store, which also delivers its updates. Its drivers are built in, and it downloads no plugins.
Limits worth knowing
- The Mac app does not use the macOS App Sandbox: it runs with your user account’s access to files and the network.
- A driver plugin runs as part of TablePro and can read the credentials of every connection you open.
More detail
What protects a database from a mistake
Safe Mode levels
Each connection has a Safe Mode level: Silent, Alert, Alert (Full), Safe Mode, Safe Mode (Full) and Read-Only. Alert asks before a write runs, the Safe Mode levels also ask for Touch ID or your Mac password, the Full levels ask before reads too, and Read-Only refuses writes. An organization can enforce a minimum level on its Macs through a configuration profile. On iPhone and iPad the levels are Off, Confirm Writes and Read-Only.
Destructive statements
At every level on the Mac, DROP, TRUNCATE and a DELETE without WHERE stop and ask first, showing the whole statement.
Limits worth knowing
- Safe Mode runs inside TablePro and guards against mistakes. It is not a sandbox or a permission system: for a rule that has to hold, use the database’s own privileges.
- New connections start at Silent, where statements run as written, an UPDATE without WHERE included.
- In the chat’s Edit and Agent modes the AI assistant can run statements, and at Silent its writes run without asking. The full-window Agent mode holds its connection at Alert or stricter, which is a reminder, not a lock.
The MCP server
Local only
The MCP server is in the Mac app only, off until you turn it on or a client you set up starts it. It listens on 127.0.0.1, with no remote mode, and clients never see a password.
How a client is approved
By default, every request needs a token with a scope (Read Only, Read & Write or Full Access), and a dialog on your Mac asks you the first time a client reaches a connection.
What a client can do
Each connection sets what outside clients may do: Blocked, Read Only (the default) or Read & Write. Writes still pass through its Safe Mode level, DROP and TRUNCATE need a Full Access token and your approval every time, and every call is logged on your Mac.
Limits worth knowing
- 127.0.0.1 says where the server listens, not who can reach it. Any program on your Mac can connect, and so can a page open on claude.ai or app.cursor.com. Each still needs a token, so keep authentication required.
- What a client reads, it sends to its own AI service under that service’s terms.
Open source
The code is public
Both apps are open source under the AGPLv3, including the code for the paid features. What this page describes can be read in the repository, with the scripts that sign and notarize each release, and you can build the Mac app yourself.
Report a vulnerability
How to report
Email [email protected], or report it privately on GitHub, in English or Vietnamese. Do not open a public issue, discussion or pull request for a vulnerability.
What to include
What is affected and its version: the Mac app, the iPhone and iPad app, a plugin or this website. Add the macOS or iOS version, the database type when a driver is involved, the steps or a proof of concept, and what an attacker gains.
Which versions get fixes
Only the latest release of each app and plugin gets security fixes, so check that the problem is still there in the latest release before you report it.