Access and trust
What runs where
Section titled “What runs where”Desktops and apps run on your Linux host. Cloud Connect stores the account and host information needed to connect you. Pilot app and host addresses are Access-protected; signalling uses an HTTPS tunnel. Media uses encrypted WebRTC with direct/STUN connectivity. Relay services, public sign-up and payments are disabled in this pilot.
Local policy still applies
Section titled “Local policy still applies”Cloud membership maps a person to an existing Linux account. The launcher still checks local admission and PAM account policy. The gateway and connector run as separate unprivileged accounts. The connector can read its own pairing, but does not belong to the gateway socket group.
Your machine, your trusted people
Section titled “Your machine, your trusted people”A Linux account is not a micro-VM. Share hosts with people you trust. Give agents their own accounts and narrowly scoped files and credentials. Do not use the beta to host mutually untrusted customers.
Protect access
Section titled “Protect access”Use unique passwords, verify your email, keep the host updated, and revoke invitations or agent tokens you no longer need. Keep a way to administer the host locally. Use HTTPS and keep the public origin exact.
Report a vulnerability
Section titled “Report a vulnerability”Contact the operator using the site’s contact link with a reproduction and affected version. Do not post tokens, passwords or private user data publicly. Independent production review and real hardware/browser validation remain launch requirements for the beta.