Machine identity
The phone verifies the enrolled machine instead of trusting a mutable address.
Security
See what is trusted, what is encrypted and which controls you can revoke today.
QR enrollment is single-use and short-lived. The scan pins the machine before the phone receives a device-specific credential.
No network location becomes permission by itself. Device identity, live access and terminal control cross separate checks.
The phone verifies the enrolled machine instead of trusting a mutable address.
WebSocket tickets expire after ten seconds and are single-use.
Observation, terminal input and administration remain distinct application capabilities.
Revoke one device, sign out others or trigger panic recovery.
Your code stays on the machine where it runs. Connections use HTTPS/WSS or private Tailscale.
Security ledger