Skip to content

Security

Security Whitepaper

A plain, honest account of how our tools treat your code and data — written for the engineers and procurement teams who evaluate us. Last reviewed September 2026.

1. The short version

  • Your code never leaves your machine. Nebula.NET obfuscates and Glass.NET decompiles entirely locally. We never receive, upload, or store your source or assemblies.
  • Builds don't depend on us. Once a machine is activated, the license works offline within its lease window — our servers being unavailable never blocks your build or your shipped app.
  • Nothing we inject phones home. A Nebula-protected assembly contains no telemetry and makes no callback to Delta1 Labs.
  • Card data never touches us. Payments run through Lemon Squeezy (Merchant of Record).

2. Local-only processing

Nebula.NET runs as a CLI, a desktop GUI, and an MSBuild/CI task — all on your machine or your build agent. Obfuscation reads and rewrites your assemblies in place; no assembly, symbol file, or source is transmitted anywhere. Glass.NET performs static analysis only — it reads metadata and IL to reconstruct C#, and never executes the assemblies it opens. Neither product requires a network connection to do its core work.

3. What leaves the machine during activation

The only network interaction is online license activation, and it exchanges the minimum needed to bind a license to a machine:

  • Sent: the license key, a machine fingerprint (a hash of hardware characteristics, used only to bind the license to that machine), and the product identifier. Never your code, assemblies, file names, or project contents.
  • Returned: a short-lived, RSA-signed lease the client caches locally.
  • Offline grace: after activation the client trusts the signed lease offline until it nears expiry, then re-verifies. If our activation endpoint is unreachable, the cached lease keeps working until it lapses — so activation-service downtime does not stall your pipeline.
  • The activation endpoint is called with a public project key that is safe to embed; it grants no access to any other customer's data.

4. Cryptography

  • Licenses & leases are signed with RSA-2048 (PKCS#1 v1.5, SHA-256) and verified against an embedded public key; a tampered license or lease fails verification and drops to the Free edition.
  • In-product protections use per-build keys: string, resource and numeric-constant encryption, control-flow flattening, optional method (IL) encryption, and an anti-tamper integrity check (a SHA-256 of the written image, verified at load).
  • All cryptography uses the platform's own System.Security.Cryptography primitives — no home-grown ciphers.

5. What runs inside your shipped product

Only the protection you asked for. A protected assembly has no telemetry, no license phone-home, and no dependency on Delta1 Labs infrastructure. If you enable method encryption, Nebula ships a small runtime helper alongside your output that decrypts methods in-process at call time — it makes no network calls. Your end users never contact us.

6. Supply-chain & build integrity

  • Obfuscation invalidates existing signatures, so Nebula re-signs the output with your key — strong-name and, optionally, Authenticode. Keys are supplied from environment variables / your CI secret store and are never written into config files.
  • Run order is enforced in guidance and tooling: publish → obfuscate → sign, so the shipped binary is both protected and validly signed.
  • Every release publishes a SHA-256 checksum to verify your download; Microsoft Store distribution is re-signed by the Store.
  • On build servers, requireLicensedEdition makes a missing or revoked license fail the build rather than silently ship weakly-protected output.

7. Data we store, and where

For licensing we store what's needed to issue and manage a license: the license key, the licensee's name/email, seat count, and a reference to the order. Payment and billing are handled by Lemon Squeezy as Merchant of Record — we never see or store card details. See our Privacy Policy. An Enterprise Data Processing Agreement is available on request, and we will delete license/account data on request subject to our legal obligations.

8. Vulnerability disclosure

We welcome responsible disclosure and operate a good-faith safe harbor. Report anything you find to security@delta1labs.com — details, timelines and scope are on our Security page. We prioritize security fixes and ship them to every version still under support.

9. Our posture, honestly

Delta1 Labs is a small, focused engineering company. We don't currently hold formal third-party certifications (SOC 2, ISO 27001), and we won't claim ones we don't have. What we do commit to is the architecture above — local-only processing, minimal data collection, no code ever leaving your machine, and transparent, verifiable releases. If your procurement process needs a security questionnaire, a DPA, or a call with an engineer, reach out and we'll work through it with a human.

Delta1 Labs · Technoparkstrasse 1, 8005 Zürich, Switzerland · security@delta1labs.com · Security · Support SLA