Trust & brand
Security
The security practices behind FLY8HT, and how to report a vulnerability.
Version 1.0 · Effective September 14, 2026
Security isn’t a page we wrote once and forgot about. It’s a real, ongoing part of how FLY8HT is built. This page describes the real, current practices, not aspirational ones.
1. Local-first is itself a security decision
The biggest security advantage FLY8HT has is architectural: there is no FLY8HT server holding your projects, builds, or credentials. Everything lives in a local SQLite database on your own machine. A breach of “our servers” can’t expose your data, because your data was never sent to one.
2. How the desktop app isolates itself
- A sandboxed renderer. FLY8HT’s UI runs with Electron’s
contextIsolationenabled andnodeIntegrationdisabled, so the interface can’t touch your filesystem, run processes, or access the network directly. It talks to the trusted main process through a narrow, typed, validated bridge only. - Every action is validated twice. Every request from the interface is checked against a strict schema on the trusted side too. The interface’s own validation is never trusted alone.
- Isolated builds. When Docker is available, a project you build runs inside its own container, never straight against your global environment. When it isn’t, builds run in a workspace-confined local process instead.
- Path-traversal and command-injection defenses. Every filesystem path FLY8HT touches is checked against the project’s own workspace boundary before use; manually-entered build/run commands go through an executable allowlist and reject shell metacharacters outright.
- Encrypted secrets, redacted logs. Environment variables you configure for a project are encrypted at rest (via the OS’s own secure storage), and stripped from every build and runtime log line before it’s ever written or shown, regardless of whether you marked it as a secret.
3. How the website handles your data
Sign-in is handled entirely by Clerk, a dedicated authentication provider, and FLY8HT never sees or stores a password. The website itself stores no payment information (it’s free) and no project data (there isn’t any to store, since that never leaves your machine).
4. Reporting a vulnerability
If you find a genuine security issue in FLY8HT (the desktop app or this website), we want to know before anyone else does. Email support@fly8ht.app with enough detail to reproduce it. We don’t currently run a paid bug bounty program, but we’ll acknowledge a genuine report, work on a real fix, and credit you (if you’d like) once it’s resolved.
Please don’t publicly disclose a vulnerability before we’ve had a reasonable chance to address it.
5. Changes to this page
As FLY8HT’s own real security work continues, this page will be updated to reflect it honestly, including disclosing real gaps that haven’t been closed yet, not just the parts that are already done.
Something wrong or unclear on this page? Tell us