Security
Security
Boardroom asks you to trust it with your plans and documents. Here is how to report a problem, what protects you today, and what does not yet.
Report a vulnerability
Please report privately through GitHub, not in a public issue. Say which component is affected, the version or commit, your platform, how to reproduce it and the impact you observed.
If private reporting is unavailable, open an issue that only asks for a private contact, without any detail. There is no committed response time yet; no release has been published, so fixes land on the main branch.
What protects you today
- Local application. No Boardroom account or server. Recorded playback makes no model calls; explicitly authorized live phases send selected context to configured OpenAI and Anthropic API routes.
- Sources on request. Authorization is checked before an external source is read, and evidence from another project is refused. This is application-level scoping, not operating-system sandboxing.
- Documents read as text. PDF files are parsed from their bytes and never run scripts; DOCX files are reduced to raw text, and HTML is never rendered or executed.
- Originals preserved. Snapshots keep the original bytes, and each export receipt records the SHA-256 of what was written.
- Verified installs. The installers check a package's SHA-256 against the release's checksums before installing anything, and the release workflow attaches a build provenance attestation to each package.
What is not proven yet
- No candidate demonstrates protection. The isolation candidates tried on Windows, Linux and macOS were blocked or failed, so command and MCP tools stay unavailable until Plan 06 qualifies one.
- Packages are not code-signed or notarized yet, and they still include development dependencies.
- Snapshots and exports are ordinary local files; saved source paths may reveal local directory names.
- Real-account qualification is pending. API keys use a host vault or explicit session injection, separately from shareable configuration. Export filtering removes known keys, but unrelated source secrets may remain. Review artifacts before sharing; cancellation does not prove zero remote billing.
Source: Plan 01 acceptance ·Plan 02 qualification ·Technical qualification ·Specification