On this page
Security and privacy
The target daemon controls terminals, files, history and client grants. Routes provide reachability and cannot expand authorization or bypass identity verification.
Identity and transport
Remote connections verify daemon identity and client credentials. SSH also verifies host keys. Investigate reinstall or wrong-target causes for changed fingerprints instead of disabling checks.
Remote terminal/file traffic is protected in transit. This does not establish broader anonymity, zero-knowledge or universal service-data guarantees.
Pairing material
Invitations are short-lived, one-time secrets redeemed into client-bound grants. Manage invitation and grant expiration separately. Revoke a lost client on every relevant target; local deletion is insufficient.
Files and shells
File tools are constrained by capabilities, path policy and OS permissions. Shells retain their OS user’s permissions; file-tool restrictions are not a shell sandbox. See file permissions.
Local data
History, logs, clipboard and screenshots may contain commands, paths, business data or accidentally printed secrets. Configure retention accordingly. Protected keys and credentials should not be published as ordinary configuration.
Cloud metadata
Cloud/Relay does not issue terminal authority, but the service processes operational account, device, network, diagnostic and usage information. Consult the site privacy policy. Local and independent SSH/Direct routes do not require terminal content to pass through Cloud.
Vulnerability reporting
Use private GitHub reporting with versions, prerequisites, a test-data reproduction and impact. Never post real keys, invitations or production content in public issues.