Skip to content

Security: danielcadev/openpad-hub

SECURITY.md

Security policy

Scope

OpenPad Hub runs locally, opens no network port and sends no telemetry. Its sensitive boundary is direct access to HID devices and controller settings.

Hardware safety rules

  • Unknown or guessed commands are prohibited.
  • Device writes are disabled unless the exact product identity and protocol are documented.
  • Every configurable write requires an automated encoder test, a previous known state, independent read-back and a verified recovery path.
  • Automated tests and demo mode use simulated hardware and never write to a physical controller.
  • Firmware updates and bootloader operations are outside the project scope.
  • Failure to confirm a change must lock writes for that session and attempt only a previously verified recovery operation.

Capture privacy

The RGB laboratory limits usbmon capture to the verified 3537:100b bus and device address and creates files with mode 0600. Captures can still contain identifiers or environmental data and are never safe to publish automatically.

Before sharing any diagnostic material, remove:

  • serial numbers and Bluetooth addresses;
  • usernames and local filesystem paths;
  • unrelated USB traffic;
  • firmware, binaries, certificates and proprietary resources.

Reporting a vulnerability

Use GitHub's private security-advisory form for vulnerabilities that could affect users. Do not open a public issue containing destructive commands, raw captures or personal identifiers.

Ordinary reproducible bugs that do not expose private information may use the public bug-report template.

There aren't any published security advisories