Ciaren

Responsible disclosure

Security

Ciaren is local-first and under active early-stage development. For responsible disclosure, see the security policy in the core repository.

Report a vulnerability

Report it privately. Please do not open a public GitHub issue or pull request for security reports.

Current controls

How Ciaren is secured today

Ciaren assumes one trusted user on their own machine. These are the protections in place today, and their limits.

Local by default

The server binds to 127.0.0.1 unless you choose another host. No Ciaren-hosted service is involved and there is no telemetry.

API token and Origin check

Set CIAREN_API_TOKEN to require a token on every /api request. Browser requests that change state must come from a configured or local origin, which blocks CSRF and DNS rebinding.

Secrets by reference

Connections store an env:, keyring:, or file: reference, never the password. Flows, .flow files, and exported code read the secret at run time.

Plugin permission approval

A plugin that declares permissions is not imported until you approve them. Plugins are not sandboxed: permissions are a disclosure and consent step.

Signed plugin packages

Ciaren verifies a detached Ed25519 signature against your trusted keys, and refuses a package whose contents do not match its signed digest.

Alpha, not yet audited

Ciaren has not completed a formal third-party security audit, and data is stored unencrypted at rest. Read the security policy before using sensitive data.