Security model
Designed for private infrastructure.
CrashPilotX is built around outbound writes, scoped tokens, RLS, and bounded data retention so crash evidence is useful without turning every machine into a public service.
No inbound ports
Agents push heartbeats and reports to Supabase. The dashboard never needs to call into your LAN.
Scoped agent tokens
Each system has its own token, so compromised credentials can be rotated by deleting/recreating that system.
RLS boundaries
Authenticated users can only manage systems, warnings, and incidents belonging to their account.
What this means operationally
Reporting a vulnerability
Every claim above is enforced in code. If you find somewhere it isn't, that's a security bug and we want to hear about it. Email saqibkhan@crashpilotx.com with SECURITY in the subject. Please don't file it publicly before a fix is out. For issues in the agent you can instead use private vulnerability reporting on the agent repository. Full details, including scope and safe harbor, are in the security policy.
Expect an acknowledgement within 5 business days and an assessment within 10. CrashPilotX is maintained by one person, so those are real targets rather than aspirational ones. Credit is given in the advisory unless you prefer to stay anonymous. There is no paid bounty.
Please test only against your own account and your own machines, or the public demo. Don't try to reach another account's systems or reports. Research that follows this policy in good faith is welcome and will not be treated as unauthorized access.
For what gets uploaded, how long it's kept, AI/model training, and secret redaction, see Data Handling.