Security
Security Whitepaper
A plain, honest account of how our tools treat your code and data — written for the engineers and procurement teams who evaluate us. Last reviewed September 2026.
1. The short version
- Your code never leaves your machine. Nebula.NET obfuscates and Glass.NET decompiles entirely locally. We never receive, upload, or store your source or assemblies.
- Builds don't depend on us. Once a machine is activated, the license works offline within its lease window — our servers being unavailable never blocks your build or your shipped app.
- Nothing we inject phones home. A Nebula-protected assembly contains no telemetry and makes no callback to Delta1 Labs.
- Card data never touches us. Payments run through Lemon Squeezy (Merchant of Record).
2. Local-only processing
Nebula.NET runs as a CLI, a desktop GUI, and an MSBuild/CI task — all on your machine or your build agent. Obfuscation reads and rewrites your assemblies in place; no assembly, symbol file, or source is transmitted anywhere. Glass.NET performs static analysis only — it reads metadata and IL to reconstruct C#, and never executes the assemblies it opens. Neither product requires a network connection to do its core work.
3. What leaves the machine during activation
The only network interaction is online license activation, and it exchanges the minimum needed to bind a license to a machine:
- Sent: the license key, a machine fingerprint (a hash of hardware characteristics, used only to bind the license to that machine), and the product identifier. Never your code, assemblies, file names, or project contents.
- Returned: a short-lived, RSA-signed lease the client caches locally.
- Offline grace: after activation the client trusts the signed lease offline until it nears expiry, then re-verifies. If our activation endpoint is unreachable, the cached lease keeps working until it lapses — so activation-service downtime does not stall your pipeline.
- The activation endpoint is called with a public project key that is safe to embed; it grants no access to any other customer's data.
4. Cryptography
- Licenses & leases are signed with RSA-2048 (PKCS#1 v1.5, SHA-256) and verified against an embedded public key; a tampered license or lease fails verification and drops to the Free edition.
- In-product protections use per-build keys: string, resource and numeric-constant encryption, control-flow flattening, optional method (IL) encryption, and an anti-tamper integrity check (a SHA-256 of the written image, verified at load).
- All cryptography uses the platform's own
System.Security.Cryptographyprimitives — no home-grown ciphers.
5. What runs inside your shipped product
Only the protection you asked for. A protected assembly has no telemetry, no license phone-home, and no dependency on Delta1 Labs infrastructure. If you enable method encryption, Nebula ships a small runtime helper alongside your output that decrypts methods in-process at call time — it makes no network calls. Your end users never contact us.
6. Supply-chain & build integrity
- Obfuscation invalidates existing signatures, so Nebula re-signs the output with your key — strong-name and, optionally, Authenticode. Keys are supplied from environment variables / your CI secret store and are never written into config files.
- Run order is enforced in guidance and tooling: publish → obfuscate → sign, so the shipped binary is both protected and validly signed.
- Every release publishes a SHA-256 checksum to verify your download; Microsoft Store distribution is re-signed by the Store.
- On build servers,
requireLicensedEditionmakes a missing or revoked license fail the build rather than silently ship weakly-protected output.
7. Data we store, and where
For licensing we store what's needed to issue and manage a license: the license key, the licensee's name/email, seat count, and a reference to the order. Payment and billing are handled by Lemon Squeezy as Merchant of Record — we never see or store card details. See our Privacy Policy. An Enterprise Data Processing Agreement is available on request, and we will delete license/account data on request subject to our legal obligations.
8. Vulnerability disclosure
We welcome responsible disclosure and operate a good-faith safe harbor. Report anything you find to security@delta1labs.com — details, timelines and scope are on our Security page. We prioritize security fixes and ship them to every version still under support.
9. Our posture, honestly
Delta1 Labs is a small, focused engineering company. We don't currently hold formal third-party certifications (SOC 2, ISO 27001), and we won't claim ones we don't have. What we do commit to is the architecture above — local-only processing, minimal data collection, no code ever leaving your machine, and transparent, verifiable releases. If your procurement process needs a security questionnaire, a DPA, or a call with an engineer, reach out and we'll work through it with a human.
Delta1 Labs · Technoparkstrasse 1, 8005 Zürich, Switzerland · security@delta1labs.com · Security · Support SLA