HydraCode
How it worksServerDownload ↓

SECURITY / DISCLOSURE

Keep the private plane private.

HydraCode accepts responsible disclosure for vulnerabilities in the desktop app, headless server, update chain, pairing, and optional sync service.

Report privately

Email security@hep.gg with affected versions, reproduction steps, impact, and any proof of concept. Do not access other users’ data, disrupt services, or publish an unpatched issue.

Update integrity

Headless artifacts are verified by SHA-256 before installation. Production releases must also use signed manifests and protected signing keys. The launcher validates a staged runtime, snapshots the database, trials the update, and rolls back on failure.

Network boundary

HydraCode advertises Tailscale first and RFC 1918 LAN addresses second. Public IPs and arbitrary public endpoints are rejected by the client configuration.

Scope

Provider platforms, Tailscale, operating systems, and Git hosts are outside HydraCode’s disclosure scope and should be reported to their maintainers.

HydraCode

Codex and Claude, on your machines.

PrivacySecurityTerms