---
title: "Security and Privacy"
url: "https://control.actana.ai/docs/introduction/security-and-privacy"
description: "Repos stay on the Core, what the Panel stores, how auth works, and the only two things that ever phone home."
updated: 2026-09-01T09:02:48+00:00
---

Your repos never leave the Core that holds them. Sessions, projects, task history, and each Harness's own credentials live in that Core's home directory. Removing a project from the Panel only unlinks it; it never touches your files.

The Panel keeps no task-shaped state. It stores the Core registry with each Core's sealed pairing credentials, the Operator login, and the presentation layer it owns (project grouping, card images, preferences).

## Auth

The browser reaches the Panel with an Operator session cookie. First boot creates the one Operator (name and password). There are no accounts, roles, or permissions on the open-source Panel.

The Panel reaches each Core over mutual TLS, pinned to the CA that Core minted at first run, plus an app-layer bearer on the core-link. The client's private key is generated on the client and never crosses the wire. You confirm the CA fingerprint before a pairing code is sent.

The Panel speaks plain HTTP and expects your proxy to terminate TLS. Core-link certificates are not something you supply or renew.

## What phones home

Once every 24 hours the Panel and each Core ask `https://api.github.com/repos/actana/control/releases/latest` whether a newer release exists, cache the answer, and — if there is one — say so in a dismissible banner and in `actana status`. Nothing is downloaded and nothing is applied. Set `ACTANA_UPDATE_CHECK=0` (or `false` / `off`) to turn the check off.

The only other outbound request is `registry.npmjs.org`, asked for the newest published version of each Harness CLI while the Providers settings page is open. **No telemetry, no analytics, no crash reporting.** Nothing describing you, your code, or your usage is sent anywhere.

## Reporting a vulnerability

Do not open a public issue. Report privately through GitHub [Security Advisories](https://github.com/actana/control/security/advisories/new). Include what you found, the version or commit, how to reproduce it, and what an attacker gets. Only the latest release is supported; a Core upgrades with `actana update`, the Panel by pulling a new image.

## See also

- [How it works](/docs/introduction/how-it-works)
- [First Operator](/docs/install/panel-installation)
- [Pairing](/docs/pairing)
- [TLS in front of the Panel](/docs/install/panel-installation)
