Flatpak’s sandbox is about to get serious attention. Germany’s Sovereign Tech Agency is putting €508,640 into hardening it. The money funds a two-year effort to develop and maintain Flatpak for the long term.
Modal Collective is co-organizing the work, with Para-Real Ltd. as the supporting organization. It ramps up over the coming months and runs through the end of 2027. Modal shared the plan in its official announcement.
Flatpak is mature, but its security model still trails Android and iOS. Some of this work had stalled. It needs specialized knowledge, and the maintainers have limited time. The funding aims to close several of those gaps.
Audio permissions are a good example. Right now, granting audio access is blunt. It’s hard to separate playback from input like a microphone. The plan adds a static PipeWire socket permission, WirePlumber policy controls, and a dedicated audio portal. An app could then use your speakers without also getting your mic.
Networking is another focus. Flatpak should gain finer network isolation. Permissions would distinguish the host, the local network, and the Internet. They’d even cover individual ports.
A dedicated VPN portal is planned too. It draws on similar APIs from Android and iOS. It would let a third-party VPN app inside the sandbox set up and manage system-level VPN connections, in a controlled way.
Password management is on the list, but still exploratory. The idea is a secure password autofill portal. It could replace browser Native Messaging, which Modal considers unfit for sandboxing.
The work goes beyond one-off portals. Developers plan an entitlements system to declare static permissions for specific portals. That helps app store reviewers see what an app actually needs. It could also enable advanced cases, like third-party accessibility tools. A related feature called “intents” would let apps advertise the services they offer.
XDG Desktop Portal gets maintenance as well. That includes a move to libdex, more integration testing, and better system permission dialogs.
The team isn’t starting from scratch. Several members worked on the 2023–2024 GNOME effort funded by the same program. The group includes Philip Withnall, Julian Sparber, Dhanuka Warusadura, Zelda Ahmed, Ignacy Kuchciński, and Hari Rana.
See also: Mastering the Linux Command Line — Your Complete Free Training Guide
It also includes Eva from the Bazaar Flatpak store and longtime GNOME designer Sam Hewitt.
The money comes from the Sovereign Tech Fund. It’s the main investment arm of Germany’s Sovereign Tech Agency. The agency backs foundational open-source projects it treats as digital infrastructure. Its priorities are security, resilience, and long-term sustainability.
FAQ
Who is funding this, and how much? Germany’s Sovereign Tech Agency, through the Sovereign Tech Fund. The investment is €508,640.
How long does the project run? About two years. It starts in the coming months and continues through the end of 2027.
What’s the headline improvement? Finer-grained permissions. For example, an app could get speaker access without your microphone.
What changes for networking? Permissions would separate the host, local network, Internet, and even specific ports. A VPN portal is also planned.
Will this affect password managers? Possibly. A secure autofill portal is planned, though still exploratory. It could replace browser Native Messaging.
Where can I read more? In Modal’s official announcement.




