The security control plane, installed where the code lives.
Apex Muster Desktop runs the local sensors that a hosted scanner cannot reach, which are the working trees, the git histories, the installed dependency graphs and, from this release, the disk itself for malware, and it files each collection under the estate's own credential so the console at /security carries one number with its coverage printed beside it.
No build on the feed yet
The release feed carries no package for this platform at the moment. When one is published it appears here with its version, its date and its checksum, read from the same manifest the application reads.
macOS 12 Monterey or later, on Apple silicon or Intel. One universal package covers both.
The macOS package is signed with a Developer ID certificate and notarized by Apple before it can reach this feed; the release path refuses to publish a package that Gatekeeper would not accept.
No build on the feed yet
The release feed carries no package for this platform at the moment. When one is published it appears here with its version, its date and its checksum, read from the same manifest the application reads.
Windows 10 or Windows 11, 64 bit. The installer offers a per-user install by default and a custom location on request.
The Windows installer is not yet code signed, so SmartScreen will ask you to confirm the publisher on first launch. Windows signing is scheduled for the next release cycle.
Four local sensors, one recorded run
The application runs the secrets muster, the filesystem preflight, the dependency audit and the malware sweep, streams the engine's output verbatim, and records a full collection with a single action. A partial collection is never filed as a run, because a coverage figure that quietly understates itself reads as a worse posture than the truth.
Malware detection with an honest engine line
The malware sensor drives ClamAV on both platforms and Microsoft Defender as the fallback on Windows. A machine with no engine reports an error rather than a clean result, and a signature set older than seven days is named with its age, because a scan can only find what its signatures knew.
Updates that verify before they install
The application checks this feed on request, downloads a new build only when asked, verifies the package against its published checksum and, on macOS, against the code signature, and installs on restart. A package that fails verification is blocked, and the application says so with the reason rather than reporting itself current.
Provenance on every screen
The status strip carries the engine that produced the last number, its hash, the tenant, the presence of the credential and the last exit code, in every view. The credential value itself never enters the window.