# Security Policy

Keebdisplay is an experimental local hardware-control tool. The daemon is intended for local development and should bind to 127.0.0.1 unless an operator has added authentication and network controls.

## Safety expectations

- Use stock firmware only.
- Prefer volatile streaming; do not persist lighting changes unless a device-specific command explicitly asks for it.
- Keep panic/stop and all-black controls reachable while testing.
- Do not expose raw device-write endpoints to a network you do not fully trust.
- Do not feed sensitive operational labels or secrets into display snapshots.
