Skip to content

Security: garethng/roampair

Security

SECURITY.md

Security Policy

Supported versions

RoamPair is pre-release software. Security fixes are applied to the current main branch only.

Threat model

RoamPair is designed for one developer operating a trusted Mac, iPhone, and self-hosted relay. The relay uses TLS and one shared bearer token. It does not provide per-peer cryptographic identity, ACLs, multi-user isolation, replay protection above TLS, or protection from a malicious relay operator.

Pairing records contain private key material. Keep them on the Mac, restrict them to the owner, and never attach them to issues or logs. Treat relay tokens, device identifiers, provisioning profiles, and diagnostic archives as secrets.

Reporting a vulnerability

Use GitHub private vulnerability reporting. If private reporting is unavailable, open an issue requesting a private contact channel without including exploit details or secrets.

Include affected components, reproduction conditions, impact, and any proposed mitigation. Please allow reasonable time for investigation before public disclosure.

There aren't any published security advisories