# Security and privacy ## Boundaries - The access token is pasted into a masked QML field, sent to the helper over stdin, and cleared immediately when the helper starts. It is then retained only by the desktop keyring and helper process memory. - Setup never places the token in argv, configuration, logs, diagnostics, or screenshots. - Configuration and cached state are mode `0600`; their directories are mode `0700`. The cache contains only registry-derived layout and sanitized states. - HTTPS is required. Plain HTTP requires explicit consent, exactly `http://homeassistant.local:8123`, and a DNS result containing only private, loopback, or link-local addresses. - HTTP redirects are rejected. WebSocket and REST requests remain on the validated configured origin. - Home Assistant REST bodies, WebSocket frames, complete WebSocket messages, registries, and state collections have hard byte or element limits before full buffering. Retained state attributes use a small allowlist with bounded strings and lists. - UI snapshots are streamed to a mode-`0600` temporary file under a hard byte ceiling and atomically replaced. The helper rejects symlinks and non-regular paths, verifies the opened inode, and returns a small offline response on read failure. The panel enforces a one-second TERM deadline followed by KILL after 250 ms, so a blocking filesystem cannot stall it indefinitely. - Home Assistant-derived values use explicit plain-text QML sinks. Values passed through shared controls are neutralized before display so they cannot be interpreted as rich text or load external resources. - The local control socket is mode `0600`. Actions are checked against domain, service, and field allowlists. - Locks and alarm panels are always status-only. Opening/closing covers requires a confirmation flag. ## Reporting Do not open a public issue containing a token, private hostname, entity names, state snapshots, or home layout. Revoke a token immediately in Home Assistant if it may have been exposed. Before release, run `scripts/check-secrets` and inspect the complete Git history. Screenshots must use the fake server and fictional rooms.