Hardened Mac app
The production target enables App Sandbox and Hardened Runtime. Virtualization, file access, and helper capabilities are declared explicitly in entitlements and build configuration.
Security and reliability by clear boundaries
SlateVM uses macOS platform security, isolates VM state into bundles, validates runtime components, and keeps privileged networking work behind a dedicated service. The result is understandable operational trust—not a black box.
The production target enables App Sandbox and Hardened Runtime. Virtualization, file access, and helper capabilities are declared explicitly in entitlements and build configuration.
Installer and disk media selected by users are retained through security-scoped bookmarks. Diagnostics keep media access visible, and the control API can refresh media references while the VM is stopped.
Release workflows sign and verify the application, helpers, nested Windows runtime, guest tools, and packages before distribution.
A computer for the agent, under your control
VM bundles, disks, configuration, console state, and provisioned SSH identities remain on systems you control unless you deliberately expose them elsewhere. MCP control terminates locally in SlateVM, console capture is scoped to the guest rather than the Mac desktop, and privileged networking is separated into its own service.
Per-VM configuration records identity, resources, media, networking, and lifecycle state. Startup reconciliation and coordinated stop and deletion paths keep processes and files aligned.
SlateVM brings media accessibility, runtime state, networking information, bounded waits, and guided remediation into one operational view.
Security depends on correct host configuration, timely platform updates, and trusted guest software. SlateVM’s architecture reduces ambiguity; it does not claim certification or eliminate the need to secure each guest.