Disclaimer
Applies to: hardenmac.com, the HardenMac Safety & Recovery Protocol, and the free tools including the open-source Mac check.
1. Experience-based, not credentialed advice
HardenMac was created by Matt, an independent developer who went through a real macOS infostealer incident, wiped and rebuilt the affected Mac, and wrote down what was learned in the process. The material is experience-based, not the output of a credentialed security practice.
HardenMac is not a licensed cybersecurity firm, managed security service provider, law firm, or financial advisory. Nothing on this site or in the Protocol should be read as coming from a certified security professional, an attorney, or a financial advisor, and none of it is professional security, legal, tax, or financial advice.
2. No guarantee of security or recovery
Every practice in the Protocol and the free tools is designed to reduce attack surface and raise the bar against common, real-world threats — not to eliminate risk. Following this material does not guarantee that any Mac, account, credential, or asset is or will remain secure; does not guarantee that a compromised device or account can be fully recovered; and does not prove, certify, or confirm that a Mac is “clean,” malware-free, or free of attacker access.
Threats, attacker techniques, and macOS itself all change over time. No document, checklist, or tool — including this one — can make a system “unhackable,” and HardenMac makes no claim that it does.
3. Not antivirus, not a scanner, not incident response
- HardenMac is documents — checklists, trackers, decision trees, and written procedures. It is not antivirus software, not an automated malware scanner, and does not install, run, or bundle any executable code as part of the paid product.
- The free, open-source Mac check (github.com/thatswhatworks/hardenmac-scan) is a read-only informational tool. It does not remove malware, does not modify the system, and — like every other part of HardenMac — does not prove a Mac is clean. An “all clear” result means no signal was found by that check, not that none exists.
- HardenMac is not professional incident response. If you are dealing with an active, high-stakes compromise — meaningful money, cryptocurrency, business systems, or highly sensitive data at risk — this material is a starting sequence, not a substitute for a qualified incident-response professional, your bank or exchange's fraud team, or law enforcement, as appropriate.
4. You are responsible for what you do with this
Any action you take based on this material — disconnecting a device, revoking sessions, rotating credentials, restoring from backup, or anything else — is your decision and your responsibility. You are responsible for your own systems, your own backups, and the consequences of the choices you make, including mistakes made while following this guidance under stress.
If money, cryptocurrency, business continuity, or highly sensitive personal or client data is at risk, consult a qualified professional before acting, and treat this material as one input among several — not the final word.
5. Educational information, provided “as is”
This material is provided for educational and informational purposes. It is offered “as is,” without warranty of any kind, express or implied — including, without limitation, any warranty of merchantability, fitness for a particular purpose, or non-infringement. See the Terms of Sale for the limitation-of-liability language that accompanies a purchase.
6. Third-party tools
Where third-party tools are named (for example Little Snitch, LuLu, the Objective-See suite, or a password manager), they are referenced and linked, never bundled or redistributed. HardenMac is not affiliated with, sponsored by, or endorsed by any of them, and makes no claim about their effectiveness beyond what their own makers state. Use of those tools is governed by their own licenses, terms, and privacy policies.
7. Malware and threat descriptions
Where this material describes attacker techniques or malware behavior, it describes behavior, not confirmed forensic attribution, unless a specific finding has been independently confirmed. Threat-family names are used advisedly and are not asserted as certain.