Is Darkbloom safe? What access it gets to your Mac
Updated
Whether Darkbloom is safe enough is your call. This page sets out what it installs, what it can do and what it tells others about your Mac, so you can decide. Everything below comes from Darkbloom’s own open-source docs (links at the end), as of late September 2026. It describes what the docs say, not an independent audit.
What gets installed and what runs
- The installer runs without sudo. It puts the darkbloom app and CLI in ~/.darkbloom, adds one PATH line to your shell file and tries to link /usr/local/bin/darkbloom.
- Two LaunchAgents run in your user account: the provider and a crash-recovery watchdog.
- The model runs inside the darkbloom process itself, with no Python interpreter or separate inference process. Darkbloom says Hardened Runtime and debugger restrictions protect that process, and the provider refuses to start with a debugger attached.
- The provider only connects out, to api.darkbloom.dev on port 443. It needs no inbound port.
- It keeps the Mac from sleeping while it serves.
- It updates itself by default: it checks at start, again after 5 minutes and then every 30 minutes, verifies each download’s checksum and code signature, and restarts after finishing accepted requests. darkbloom autoupdate disable turns this off.
- Fan control is optional and off by default. If you turn it on, it installs a root helper that can only set fan speeds and receives no prompts, keys or network access.
What your Mac sees of other people’s requests
- Requests reach your Mac encrypted. Your Mac is where they are decrypted: the prompt and the answer exist in plain text inside the provider process while it runs the model.
- Darkbloom’s docs say prompts are decrypted only inside that process and never logged. Provider logs hold request ids, model ids and token counts.
- Your Mac never sees the customer’s API key, identity or balance.
- Darkbloom’s docs are open about limits: the process protections don’t guarantee that every prompt or answer is wiped from memory after inference, and Darkbloom’s coordinator also reads each request in memory to route and bill it.
- Provider logs are not uploaded automatically. darkbloom report sends a log excerpt only when you run it, and --dry-run shows it first.
What Darkbloom keeps about your Mac
Darkbloom’s coordinator stores your Mac’s Secure Enclave public key, chip and model, and on the MDM path also its serial number, UDID, push token and Apple device-attestation certificate chain. It receives regular heartbeats with operational data such as status, memory and thermal state, in a fixed format rather than free text, so they can’t carry prompts.
The MDM profile (macOS before 27)
- On macOS before 27, Darkbloom verifies your Mac through its own MDM profile. MDM lets Darkbloom ask Apple’s management system, not its own software, whether System Integrity Protection and Secure Boot are on.
- The profile requests three read-only rights: inspect installed profiles, query device information and run security queries.
- It does not request the rights to install or remove profiles, lock the Mac or change its passcode, erase it, list installed apps, apply restrictions, change settings or manage apps.
- Darkbloom’s coordinator sends only two MDM commands: SecurityInfo (SIP and Secure Boot state) and DeviceInformation (for Apple’s device attestation). Its code refuses to send any other command.
- The coordinator has no right to remove the profile. You can remove it yourself at any time in System Settings → General → Device Management, though the Mac then loses verification. On macOS 27, wait until App Attest is confirmed first.
- A Mac already managed by another MDM, such as an employer’s, can’t use this path.
App Attest on macOS 27
- Since Darkbloom 0.9.7, Macs on macOS 27 or later can be verified with Apple’s App Attest instead, with no Darkbloom MDM profile. New setups on macOS 27 skip the profile.
- Darkbloom says its MDM will be switched off soon and recommends upgrading to macOS 27.
- Already enrolled? Upgrading macOS doesn’t remove the profile. Keep it until Darkbloom reports removal is ready, then run darkbloom unenroll and choose the App Attest option. The command guides you to remove the profile in System Settings; it doesn’t remove anything itself.
- Company-managed Macs keep their employer profile on this path.
What it requires of your Mac
- System Integrity Protection on and Secure Boot at Full Security. A Mac that reports either one off is marked untrusted at once.
- A user logged in at the Mac’s screen, automatic login on, auto-logout off and sleep prevented, so the Mac can be verified again after a reboot.
- A released provider build. If the provider binary or model files change from what the Mac registered, it is marked untrusted; darkbloom update returns it to a released build.
- Darkbloom treats a single Mac as its security boundary. Linking Macs over Thunderbolt (RDMA) bypasses the process protections and is not trusted.
What anyone can see
- Darkbloom’s public attestation endpoint shows each Mac’s verification verdict: trust level, MDM and device-attestation flags and the verified security settings. It never shows the serial number, UDID or push token.
- Darkbloom’s public stats list every connected Mac’s chip, memory, macOS version, loaded model and request counts, without names.
How to remove it
- If you turned on fan control: sudo darkbloom fan uninstall.
- darkbloom stop --uninstall finishes accepted requests, stops the provider and removes both LaunchAgents.
- darkbloom unenroll, choosing full exit, guides you to remove the MDM profile (if you have one) and offers to delete the local config, login token and Secure Enclave key. Your account history on Darkbloom’s side stays.
- Delete downloaded models with darkbloom models remove <id> while the CLI is still installed. They live in ~/.cache/huggingface/hub.
- Then delete ~/.darkbloom and ~/.config/darkbloom, remove /usr/local/bin/darkbloom (needs sudo) and delete the # Darkbloom PATH line from your shell file.
What the docs don’t cover
Darkbloom’s technical docs don’t cover legal questions, such as responsibility for what strangers ask your Mac to generate. Read Darkbloom’s terms if that matters to you.
Sources
- Encryption and privacy model: github.com/Layr-Labs/d-inference/blob/master/docs/architecture/security/encryption.md
- Privacy expectations: github.com/Layr-Labs/d-inference/blob/master/docs/consumer/privacy-expectations.md
- MDM enrollment (profile rights): github.com/Layr-Labs/d-inference/blob/master/docs/architecture/security/enrollment.md
- Provider attestation guide: github.com/Layr-Labs/d-inference/blob/master/docs/provider/attestation.md
- Attestation architecture: github.com/Layr-Labs/d-inference/blob/master/docs/architecture/security/attestation.md
- Provider process: github.com/Layr-Labs/d-inference/blob/master/docs/architecture/components/provider.md
- Install, update and uninstall: github.com/Layr-Labs/d-inference/blob/master/docs/provider/installation.md
- CLI reference (unenroll, stop, auto-update timing): github.com/Layr-Labs/d-inference/blob/master/docs/provider/cli-reference.md
- Hardware requirements (network, sleep): github.com/Layr-Labs/d-inference/blob/master/docs/provider/hardware-requirements.md
- Release notes (0.9.7 App Attest without MDM): github.com/Layr-Labs/d-inference/releases
How BloomGauge helps
BloomGauge is an independent app, not affiliated with Darkbloom, and it runs locally. It reads the provider’s state file and your confirmed earnings using the provider’s existing login, makes model changes only through Darkbloom’s own CLI and keeps its history on your Mac. It never touches payouts, withdrawals, fans or power settings, and never uploads your credentials.
Questions
Is Darkbloom safe to run on my Mac?
That is your call. Per Darkbloom’s docs, the provider installs in your user account without sudo, connects out only, updates itself, keeps the Mac awake and runs strangers’ requests inside its own protected process. On macOS before 27 it uses a read-only MDM profile; on macOS 27 it can use App Attest instead.
What can the Darkbloom MDM profile do?
It requests only read-only rights: inspect installed profiles, query device information and run security queries. Darkbloom’s coordinator sends only SecurityInfo and DeviceInformation commands, to confirm SIP and Secure Boot. It cannot erase or lock the Mac, install apps or profiles, or change settings, and you can remove it in System Settings.
Can Darkbloom providers read my prompts?
The Mac that serves a request decrypts it inside Darkbloom’s provider process, which is where the model runs. Darkbloom says prompts are never logged and the process is protected by Hardened Runtime and debugger restrictions, but its docs also say the provider sees the prompt and completion in plain text and doesn’t guarantee memory is wiped afterwards.
How do I uninstall Darkbloom?
Run darkbloom stop --uninstall, then darkbloom unenroll and choose full exit, remove downloaded models with darkbloom models remove, and delete ~/.darkbloom, ~/.config/darkbloom and /usr/local/bin/darkbloom. Remove the MDM profile in System Settings if you have one.
Related
- Darkbloom verification pending: MDM, App Attest and trust on macOS 27
- Is Darkbloom worth it on a Mac?
- Darkbloom provider on a Mac: setup checklist
- darkbloom unenroll errors: moving from MDM to App Attest, step by step
Updated 2026-09-29. Still stuck? Ask in #bloomgauge on the Darkbloom Slack or contact us. BloomGauge is independent and not affiliated with Darkbloom.