Safety

Are Mac notch apps safe? How to check one yourself

A notch app is as safe as the people who made it, and you can check two things before you trust one. First, whether macOS knows who made it and Apple has scanned it: run spctl -a -vv on the app, and “accepted” with “source=Notarized Developer ID” means it is signed and notarized. Second, what it can see: the permissions it asks for, listed in System Settings, Privacy & Security, each of which should match a feature you use. Open source helps too, because anyone can read the code, but it does not replace either check.

Last updated: October 2026

Written by the developer of Crest, 7 October 2026. Every command on this page was run that day on a 16-inch MacBook Pro (Mac16,7) on macOS 27.0.1, on Crest 6.4.0 and Take 4.0.0 as crestnotch.app serves them (the paths show where macOS normally mounts the disk image), and on two small test apps we built to show what a rejection looks like. Other notch apps are described from their own sites, READMEs and release notes, read the same day; we did not install them, so where a maker says nothing about signing, this page says we could not verify it.

What notarized means, and what it does not

Apple calls notarization “an automated system that scans your software for malicious content, checks for code-signing issues”. A developer signs the app with a Developer ID, a certificate Apple issues to a named person or company, and sends it to Apple. If the scan finds nothing, Apple issues a ticket, and the developer can staple it to the app so a Mac can check it offline.

When you open a downloaded app, Gatekeeper checks that it “is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered”. An app that fails is stopped with a warning. Since macOS Sequoia you can no longer Control-click past it: you go to System Settings, Privacy & Security and click Open Anyway, which Apple says is available “for about an hour after you try to open the app”.

What it does not mean: Apple says plainly that “Notarization of macOS software is not App Review.” Nobody at Apple decides whether the app is good, or reads what it does with your data. It means a known developer signed it, a scan found no known malware, and it has not been changed since. Apps from the Mac App Store go further: Apple reviews them and they run in a sandbox.

Check any app yourself

You need Terminal, nothing else. Drag the app onto the Terminal window to type its path for you.

  1. Is it signed and notarized? Type spctl -a -vv , drag the app in, press Return.
  2. Who signed it? Type codesign -dv --verbose=4 , drag the app in, press Return.
  3. What will it ask for? Type plutil -p , drag the app in, add /Contents/Info.plist | grep UsageDescription, press Return.

Here is Crest 6.4.0, from the disk image crestnotch.app serves, on 7 October 2026:

$ spctl -a -vv /Volumes/Crest/Crest.app
/Volumes/Crest/Crest.app: accepted
source=Notarized Developer ID
origin=Developer ID Application: Zakaria Swaidan (SA6A94K2Y4)

accepted with source=Notarized Developer ID is the answer you want, and origin names the developer. Take 4.0.0 gave the same answer.

$ codesign -dv --verbose=4 /Volumes/Crest/Crest.app
Identifier=com.zack40x.crest
Format=app bundle with Mach-O universal (x86_64 arm64)
CodeDirectory v=20500 size=96285 flags=0x10000(runtime) hashes=2998+7 location=embedded
Authority=Developer ID Application: Zakaria Swaidan (SA6A94K2Y4)
Authority=Developer ID Certification Authority
Authority=Apple Root CA
Timestamp=6 Oct 2026 at 8:14:02 PM
Notarization Ticket=stapled
TeamIdentifier=SA6A94K2Y4

Notarization Ticket=stapled means the ticket travels inside the app, and flags=0x10000(runtime) is the hardened runtime, which Apple requires for notarization. xcrun stapler validate checks the ticket too, if you have Apple’s command line tools.

And this is what failing looks like. We built a tiny app with no signature, and checked Apple’s own Calculator for comparison:

$ spctl -a -vv Hello.app
Hello.app: rejected
source=no usable signature

$ spctl -a -vv /System/Applications/Calculator.app
/System/Applications/Calculator.app: accepted
source=Apple System
origin=macOS Software Signing

Our second test app, signed but with no developer behind the signature (an “ad hoc” signature, TeamIdentifier=not set in codesign), was rejected too. A signature alone is not enough: Gatekeeper wants a Developer ID with Apple’s notarization, or an app from the App Store.

The third command lists the reason the app gives macOS for each permission it might ask for, in its own words:

$ plutil -p /Volumes/Crest/Crest.app/Contents/Info.plist | grep UsageDescription
  "NSAppleEventsUsageDescription" => "Crest controls Music and Spotify to show and manage what's playing from your notch."
  "NSBluetoothAlwaysUsageDescription" => "Crest shows the battery level of your connected Bluetooth devices in the notch."
  "NSCalendarsFullAccessUsageDescription" => "Crest shows your next meeting in the notch and lets you join the call with one tap."
  "NSCameraUsageDescription" => "Crest shows you a quick camera check before you join a meeting. The camera is on only while the check is open."
  ...

Every line should match something the app does. A notch app with a microphone line and no feature that listens would be worth a question to its maker.

What a notch app asks for, and why

A notch app needs no permission to draw in the notch. The prompts come with features, and macOS asks once per permission, the first time a feature needs it. You can see and switch off every one in System Settings, Privacy & Security.

PermissionWhat it lets an app doWhy a notch app asksWhat Crest uses it for
AccessibilityRead and control other apps’ windows and send keys: the most powerful one hereMoving windows, catching the media keys, typing into another appWindow snapping, the media keys, and typing an answer into an agent’s terminal
Screen & System Audio RecordingSee and record everything on screen, and the Mac’s soundScreen recording, or reading colours off the screenScreen recordings started from the Shelf
AutomationControl one named app, such as Music or System EventsPlaying, pausing and seeking in Music or SpotifyMusic and Spotify controls, and the Dark Mode switch
Calendars, RemindersRead your events or to-dos, and add new onesThe next meeting in the notch, a to-do listYour next meeting and its Join button; to-dos
Full Disk AccessRead files that are otherwise protected, including other apps’ dataMirroring macOS notificationsOnly the optional macOS notifications on the notch
Microphone, CameraListen or see while the app is using them; macOS shows a dot in the menu barA mirror, a voice note, a call checkThe camera check before a meeting, talking to Claude, the teleprompter
BluetoothSee nearby and connected devicesHeadphone and mouse batteriesAirPods and device batteries

Accessibility deserves the most care: Apple’s guide describes it as letting an app “access and control your Mac”, and an app holding it can read other windows and type. Give it to an app you trust, for a feature you use. Crest asks for each permission only when you turn on the feature that needs it, and its Settings, General, Permissions lists every one with what it is for and a button to the right switch.

Open source or closed?

Open source means anyone can read the code, which is a real safeguard: The Boring Notch, Atoll and DynamicNotch are open source under the GPL. But you download a built app, not the code, and only the signature ties the app to a known developer. Closed apps such as Crest, Alcove and Vibe Island ask you to trust the maker, and a Developer ID and notarization make that maker a known name to Apple. Neither kind is safe or unsafe by default; the two checks above tell you more than the licence does.

A notarized alternative to The Boring Notch?

The Boring Notch is free and open source, and its README says why macOS warns about it: the team does not have an Apple Developer account yet, so the app is not notarized. Its README offers xattr -dr com.apple.quarantine on the app, which removes the “downloaded from the internet” flag so Gatekeeper does not check it at first launch, or Apple’s Open Anyway button. That does not make the app harmful; it means Apple’s scan has not seen that build, and you are taking the code on trust. Apple’s own guide says overriding these settings is “the most common way that a Mac gets infected with malware”, which is a reason to do it only for an app whose source you trust.

If you want one that macOS accepts without that step: Crest is signed and notarized, as the output above shows, and its free tier covers what The Boring Notch is mostly used for, music in the notch and a file shelf. NotchDrop, a free file shelf, comes from the Mac App Store. For the rest, here is what each maker says, read 7 October 2026. Where a site says nothing, we could not verify it either way, so run spctl on the download yourself.

AppOpen sourceWhat its maker says about signing
CrestNoSigned with a Developer ID and notarized, ticket stapled: the spctl and codesign output above, 7 October 2026
The Boring NotchYes, GPL-3.0README: “We don’t have an Apple Developer account (yet…), so macOS will warn you that Boring Notch is from an unidentified developer”. It gives an xattr command or Open Anyway to get past the warning
AtollYes, GPL-3.0Not stated in its README or release notes
DynamicNotchYes, GPL-3.0README: “If macOS blocks the first launch, allow it from System Settings > Privacy & Security”
NotchDropYes, MITFree on the Mac App Store, so Apple reviews it and it runs in the App Store sandbox
AlcoveNoNot stated on tryalcove.com
Vibe IslandNoNot stated on vibeisland.app; its terms mention a Mac App Store edition
DroppyCould not verify: its GitHub page answers “Unavailable For Legal Reasons”Not stated on getdroppy.app
TopNotchNot statedNot stated on topnotch.app

How the two compare feature by feature: Crest vs The Boring Notch.

What Crest can see, and what it sends

Crest’s entitlements, the switches signed into the app, ask for four things: sending Apple events (controlling Music and Spotify), the microphone, the camera and your calendars. Anything else is a permission you grant in System Settings when you turn a feature on. What leaves the Mac is listed in our privacy policy: licence and update checks, an anonymous install count you can turn off, and what a widget fetches for you, such as the weather or a song’s lyrics. Updates come through Sparkle, which checks each one against a key built into the app before installing it.

Sources

FAQ

Are Mac notch apps safe?

A notch app is as safe as its maker. Check that macOS accepts it (spctl -a -vv on the app should say accepted, source=Notarized Developer ID) and that each permission it asks for matches a feature you use. Accessibility is the powerful one: it lets an app control other windows.

Is The Boring Notch safe?

It is free and open source, so anyone can read its code. Its README says it is not notarized because the team has no Apple Developer account yet, so macOS warns at first launch and you let it through with Open Anyway or an xattr command. We have not installed it, and that warning is not a sign of malware; it means Apple's scan has not checked that build.

Is there a Boring Notch alternative that is notarized?

Yes. Crest is signed with a Developer ID and notarized, with the ticket stapled: spctl reports accepted, source=Notarized Developer ID. Its free tier has Now Playing and a file shelf. NotchDrop, a free file shelf, is on the Mac App Store. Most other notch apps do not say on their sites whether they are notarized.

What does notarized mean on a Mac?

That Apple's automated service scanned the app for known malware and code-signing problems and issued a ticket for it. It is not App Review: nobody at Apple judges what the app does. It does tell you a known developer signed it and that it has not been changed since.

How do I check if a Mac app is notarized?

Open Terminal, type spctl -a -vv followed by a space, drag the app onto the window and press Return. accepted with source=Notarized Developer ID means it is notarized; rejected means Gatekeeper would stop it. codesign -dv --verbose=4 shows who signed it and whether the ticket is stapled.

Why does a notch app need Accessibility permission?

To move other apps' windows, catch the media keys or type into another app. Crest uses it for window snapping, the media keys and typing an answer into an agent's terminal, and asks only when you turn one of those on. A notch app needs no permission just to draw in the notch.

Is it safe to remove the quarantine flag with xattr?

It turns off Gatekeeper's first-launch check for that one app, the same as Apple's Open Anyway button. Do it only for an app whose source you trust: Apple's guide calls overriding these settings the most common way a Mac gets infected with malware.

Try Crest free

Download it with no account. Now Playing, the Shelf, the Clipboard and window snapping are free for good, and signing in gives you 7 days of Pro with no card. Pro, with Take and Minutes, is $24.99 once, on 2 Macs, or $2.99 a month.

Download Crest for macOS Get Crest Pro, $24.99

macOS 14 Sonoma or later · signed and notarized by Apple · 7-day refund

Keep reading: Clipboard history on a Mac · Snap windows on a Mac · File shelf apps for the notch · Crest vs The Boring Notch · Best Mac notch apps in 2026 · Crest overview