Security and Privacy

Your repos never leave the Core that holds them. Sessions, projects, task history, and each Harness's own credentials live in that Core's home directory. Removing a project from the Panel only unlinks it; it never touches your files.

The Panel keeps no task-shaped state. It stores the Core registry with each Core's sealed pairing credentials, the Operator login, and the presentation layer it owns (project grouping, card images, preferences).

Auth

The browser reaches the Panel with an Operator session cookie. First boot creates the one Operator (name and password). There are no accounts, roles, or permissions on the open-source Panel.

The Panel reaches each Core over mutual TLS, pinned to the CA that Core minted at first run, plus an app-layer bearer on the core-link. The client's private key is generated on the client and never crosses the wire. You confirm the CA fingerprint before a pairing code is sent.

The Panel speaks plain HTTP and expects your proxy to terminate TLS. Core-link certificates are not something you supply or renew.

What phones home

Once every 24 hours the Panel and each Core ask https://api.github.com/repos/actana/control/releases/latest whether a newer release exists, cache the answer, and — if there is one — say so in a dismissible banner and in actana status. Nothing is downloaded and nothing is applied. Set ACTANA_UPDATE_CHECK=0 (or false / off) to turn the check off.

The only other outbound request is registry.npmjs.org, asked for the newest published version of each Harness CLI while the Providers settings page is open. No telemetry, no analytics, no crash reporting. Nothing describing you, your code, or your usage is sent anywhere.

Reporting a vulnerability

Do not open a public issue. Report privately through GitHub Security Advisories. Include what you found, the version or commit, how to reproduce it, and what an attacker gets. Only the latest release is supported; a Core upgrades with actana update, the Panel by pulling a new image.

See also

Built by Qcentic