Security & local data

A local desktop workflow, by design.

RPL Engine Workbench is a native Windows 11 and Apple silicon Mac application. The core sizing, geometry, reporting, and export workflows run on your machine, and your project files stay where you save them.

Last updated July 15, 2026.

Runs on your computer

The core sizing, injector and nozzle workflows, reporting, and export run locally on Windows 11 or an Apple silicon Mac. There is no cloud requirement for the core engineering workflow and no browser-based engineering state.

Your files stay local

Project cases, PDF reports, DXF geometry, images, videos, and other exports are written to local disk locations you choose. They are not uploaded to Rocket Propulsion Lab as part of the core workflow.

Trial and licensing

Trial mode requires no license key. Activation, periodic validation, and deactivation communicate with Freemius over HTTPS and may send the license key, product/user/license/install identifiers, a one-way device identifier, activation state, and purchase email or other account fields when requested. Project data and engineering outputs are not included.

Local integrations

RocketCEA is an optional local Python integration that you install and configure. FFmpeg is bundled with the Windows beta for local MP4 export; on Mac it is an optional local tool. These integrations run on your machine.

License storage

The macOS release stores the local license record in the user’s Keychain and refuses a plaintext fallback in customer release mode. The Windows public beta stores its license record in user-scoped application settings; that record is not protected by Windows Credential Manager or DPAPI. Protect the Windows user account and do not share its settings profile.

Offline behavior

The core workflow does not require an always-on connection. Paid licenses are periodically validated and currently have a 14-day offline grace period after the last successful validation. Activation and deactivation require a connection.

What this page is and is not

This describes the current public build at a high level; it is not a formal security certification or a penetration-test report. For organization-specific security review, contact support@rocketpropulsionlab.net.

Website

The website and desktop app have separate data paths.

The site uses cookie-free, first-party aggregate measurement and may load Freemius checkout JavaScript on purchase pages. It does not load advertising trackers or receive engineering project data. Download, licensing, and contact requests use normal links, email, or Freemius checkout. See the Privacy Notice for fields and retention.

Questions about data handling?

If your organization needs a written summary of how the application and licensing path handle data, reach out and we will provide what we can confirm.

support@rocketpropulsionlab.net

Vulnerability disclosure

Report a security issue privately.

Email support@rocketpropulsionlab.net with the affected version or URL, reproduction steps, impact, and a safe proof of concept. Do not include sensitive project data or license keys. Our machine-readable contact is at /.well-known/security.txt.

In scope
rocketpropulsionlab.net and the current public Windows and macOS releases of RPL Engine Workbench
Out of scope
Freemius, Namecheap, email infrastructure, and other third-party services; report those directly to the provider
Research rules
Do not access other people’s data, disrupt service, use social engineering, perform denial-of-service testing, or retain data beyond what is needed to demonstrate the issue
Disclosure
Keep the report confidential while we investigate and coordinate a reasonable disclosure date; no bounty is currently offered

Rocket Propulsion Laboratory LLC will not pursue claims solely for good-faith security research that follows this policy, avoids privacy and service harm, and complies with applicable law. This safe-harbor statement does not bind third parties.