Trust center
Security without theater.
Desktop safeguards
- Context isolation, renderer sandboxing, navigation blocking, and narrowly scoped audio-only permissions.
- Secrets encrypted through the operating system when secure storage is available.
- HTTPS-only public services and checkout links; SHA-256 verification before updater launch.
- No automatic external safety reporting and no payment-card storage.
Release integrity
Official releases include checksums, an SBOM, privacy declaration, code-signing status, and build provenance. The current Windows build Eidovara-0.18.3-Windows-x64-Setup.exe (about 101.3 MiB) is not Authenticode-signed and is not Microsoft-certified; verify SHA-256 4C6D9FA2B0CB4667C1B6580551632618DEB12B5CF5947457474BAEC0DFA7740E and GitHub attestation. Provenance is not Authenticode.
Website helper
Ask Eidovara answers from an allowlisted knowledge pack. Optional /v1/assist accepts a single question, refuses desktop conversation history, and does not store transcripts. Tight Content-Security-Policy on these pages; connect is limited to this origin and HTTPS.
Network inventory
Current egress is Wikipedia/Wikimedia after an explicit research request, optional pasted HTTPS model providers, Premium Brave with a user key, official GitHub update checks, optional Worker /health, /v1/config, /v1/status (desktop, default https://api.eidovara.org) and /v1/assist (website helper after a saved HTTPS base), and Spotify/YouTube HTTPS search links. See NETWORK-USAGE.md. Payments stay fail-closed. No workers.dev host is compiled into the app. Local media uses media-src https: eidovara-media:, never media-src 'self'.
Not enabled
v0.18.3 does not bundle neural TTS, VRM, or OBS websocket control, and does not turn on live checkout. Dependency review continues to fail on moderate severity. The renderer stays sandboxed. These are product limits, not a perfect-security or PCI claim. Adults 18+. Source-available, not open source. Authenticode-unsigned Windows.
Report a vulnerability
Use the repository’s private security-advisory channel when available. Never place credentials, private keys, personal records, or exploit details in a public issue. No software is guaranteed perfectly secure.