Gleam

Security

Effective 21 September 2026 · Applies to the Gleam desktop app for Windows and to this website.

Found a problem? Please email mwaibryn@gmail.com with "Gleam security" in the subject. Tell us privately first and give us a fair chance to fix it before you share it with anyone else.

1. How to report

We aim to reply within 5 working days and to tell you what we will do and when. We are glad to credit you when the fix ships, if you would like that. There is no paid bug bounty.

2. What is in scope

Out of scope: the AI and voice services Gleam connects to (Anthropic, OpenAI, NVIDIA, Groq, Fish Audio), GitHub itself, and problems that need someone to already control your Windows account. Please report issues with those services to them directly.

Please test only on your own computer and your own accounts. Do not access other people's data, and do not run tests that degrade services for others.

3. How Gleam is built to be safe

4. Check your download

Download Gleam only from this website. Each release lists the SHA256 checksum of its installer. To check yours, open PowerShell in your Downloads folder and run:

Get-FileHash .\Gleam_0.1.0_x64-setup.exe -Algorithm SHA256

The result must match the checksum on the download card exactly. If it does not, delete the file and tell us. The installer is not yet code-signed, so Windows SmartScreen may warn you the first time; the checksum is how you confirm the file is ours.

5. This website

This site is static HTML served by GitHub Pages over HTTPS. It sets no cookies, has no forms and loads no scripts, fonts or analytics from anyone else.