DocumentationConfiguration
Rust · 0.1.0
Security checklist
Protect accounts, private notes, credentials and outgoing integrations.
Before exposing an instance
Finish initial account setup on a private listener, enable HTTPS, and review registration and instance access settings. Keep rate limiting enabled and configure proxy trust deliberately. Demo mode uses deterministic demo data and a fixed signing secret, so it must never hold private production records.
- Use least-privilege service and database accounts
- Keep data directories and backups out of the web root
- Test anonymous access with a separate browser session
- Revoke unneeded tokens, share links and integration credentials
Content and external services
Private memo visibility is an application access rule, not end-to-end encryption from the server operator. Administrators and storage operators have privileged responsibilities. Webhooks and AI providers can receive user content when used; review their destination and data scope before enabling them. Keep private-network webhook exceptions narrow instead of disabling outbound checks broadly.
Stay recoverable
Record the deployed source and image, protect backups and rehearse restoration. Check access again after proxy, authentication or visibility changes. A healthy process is not evidence that permissions or backups are correct.