SECURITY / DISCLOSURE
Keep the private plane private.
HydraCode accepts responsible disclosure for vulnerabilities in the desktop app, headless server, update chain, pairing, and optional sync service.
Report privately
Email security@hep.gg with affected versions, reproduction steps, impact, and any proof of concept. Do not access other users’ data, disrupt services, or publish an unpatched issue.
Update integrity
Headless artifacts are verified by SHA-256 before installation. Production releases must also use signed manifests and protected signing keys. The launcher validates a staged runtime, snapshots the database, trials the update, and rolls back on failure.
Network boundary
HydraCode advertises Tailscale first and RFC 1918 LAN addresses second. Public IPs and arbitrary public endpoints are rejected by the client configuration.
Scope
Provider platforms, Tailscale, operating systems, and Git hosts are outside HydraCode’s disclosure scope and should be reported to their maintainers.