Last updated: October 1, 2026
Security
dayzero.run is designed to remove infrastructure setup while keeping the security boundaries visible. This page describes the current model and how to report a problem.
Current protections
- Project and API traffic uses HTTPS on dayzero.run domains.
- Passwords are stored as password hashes rather than readable passwords.
- CLI requests authenticate with an account API token.
- Private projects require a generated 6-digit access code before project files are served.
- Project files and account metadata are separated by project and account identifiers.
Your security responsibilities
- Keep your API token out of source control, screenshots, browser code, and public agent transcripts.
- Use
VIBEPAGE_TOKENor the d0 token store instead of hard-coding a token. - Rotate credentials and contact us if you believe a token or account has been exposed.
- Review static build output before deployment so it does not contain secrets or private source files.
- Only tunnel a local service you intend to expose publicly.
Private project limitation
The 6-digit private-project code is lightweight sharing control. It is not a replacement for identity-based authentication, authorization roles, or protection of regulated and highly sensitive data.
Report a vulnerability
Email hello@dayzero.run with “Security report” in the subject. Include the affected URL or component, reproduction steps, impact, and a safe way to contact you. Please avoid accessing other users’ data, disrupting the service, or publishing details before we have had a reasonable opportunity to investigate.
Response
We will acknowledge credible reports, investigate their impact, and prioritize fixes based on severity. We may ask for additional details while reproducing the issue.