Account access
Verified email, HTTP-only session cookies, password controls, and server-side authorization protect publisher actions.
DistKit keeps production IPA objects private and applies authorization or share-link policy before serving a manifest or file. Security claims on this page describe implemented controls, not certifications.
The security model follows the account, record, object, link, and device data path.
Verified email, HTTP-only session cookies, password controls, and server-side authorization protect publisher actions.
Production data uses Supabase Postgres with row-level security; service credentials remain server-side.
Objects are private in Cloudflare R2 and are served through Worker routes after account or share-link policy checks.
Password, expiry, manifest-request limit, enabled state, App status, and Release status are evaluated before delivery.
The explicit device flow returns the UDID, hardware model identifier, and iOS version. It does not enroll MDM, and its session expires after about 15 minutes.
Reports can be reviewed, links or Apps can be restricted, and moderation actions are recorded for investigation.
Accurate limits are part of the product contract.
Parse metadata and provisioning information, enforce its own access policy, and keep IPA delivery behind controlled routes.
Re-sign the IPA, bypass Apple policy, guarantee device eligibility, confirm completed installation, or claim certifications it has not earned.
Certificates, profiles, entitlements, authorized Enterprise use, device registration, export settings, and tester authorization.
Review the public policies or contact support before distributing sensitive builds.
Start with an already-signed IPA and keep the Release private until its report and link policy are ready.