Local-first by default
RelayHub is designed to keep essential operation local where practical and avoid hidden dependency on centralised services.
Security
RelayHub is being designed as local-first infrastructure for resilient communities. Security claims must remain realistic, testable, and clear.
Security posture
RelayHub should reduce unnecessary exposure, support local operation, preserve recovery paths, and make capability boundaries visible. It must not overstate privacy, anonymity, censorship resistance, or operational safety.
RelayHub is designed to keep essential operation local where practical and avoid hidden dependency on centralised services.
Services should run with only the access they need, and administrative control should not be exposed unnecessarily.
Features should only activate when hardware, software, policy, trust, legal, runtime, and user gates allow them.
Recovery, rollback, safe reset, support export, and identity preservation are treated as core architecture rather than optional extras.
Threat boundaries
Honest security starts by naming limits. RelayHub is intended to support resilient communication and community coordination, but it must never be described as invulnerable, perfectly anonymous, or guaranteed under all conditions.
Responsible disclosure
If you discover a vulnerability, privacy issue, unsafe behaviour, or misleading security claim, please report it responsibly. Do not exploit systems, access other people’s data, disrupt services, or publish active vulnerabilities before there has been time to assess and respond.
Recovery-first
Security controls that make ordinary recovery impossible can create fragility. RelayHub designs should preserve safe rollback, guided recovery, identity continuity where possible, and privacy-preserving support export.
No convenience feature should silently increase exposure. No update should silently enable new sharing, new federation, new gateway behaviour, or new radio transmission without clear policy permission and validation.
Contact
Use the contact form for security reports and include as much detail as possible: affected page, endpoint, expected behaviour, observed behaviour, reproduction steps, browser or device context, and whether any data may have been exposed.
Email: hello@relayhub.tech
Contact form: relayhub.tech/contact