Skip to content

Security: mycyg/NovelCast

Security

SECURITY.md

Security

NovelCast binds its local API to 127.0.0.1 and requires a per-launch bearer token. Provider credentials are stored in macOS Keychain by the desktop app and are passed to a provider process only for the duration of a request.

Never place credentials in project files, Markdown mirrors, environment example files, logs, issue reports, or Git history. If a key is accidentally shared, revoke it at the provider immediately and create a replacement.

Imported reference voices remain local. The user is responsible for ensuring that a voice reference is lawfully obtained and used.

There aren't any published security advisories