Security
Security
Report a problem
Found a vulnerability? Please write to support@houjun.dev with the subject “VoxStage security” before telling anyone else, and do not open a public issue for it. Say what you found, how to reproduce it and which version (commit) you used. We will acknowledge your report, keep you informed, and credit you when it is fixed if you wish. There is no bug bounty.
Machine-readable contact: security.txt; this page is the policy it points to.
How VoxStage is built to be safe
- Local by default. The service listens on this Mac only (127.0.0.1). Nothing is exposed to the network unless you start it in network access mode.
- Network access mode is locked. Other devices need an access key; the browser keeps only a hash of it, and requests from other sites are refused, so a web page you visit cannot drive VoxStage.
- Every request is checked. Requests must carry VoxStage's own header; project and voice ids are checked against a fixed shape before they touch a file.
- Packages cannot reach outside. A
.voxstagepackage is checked as a whole before anything is written: its paths against a fixed list of shapes, its size, links, and every file's SHA-256. It never overwrites existing work. - Models are verified. Each model is pinned to a revision and checked by SHA-256 before it is used.
- Consent is enforced in code. A voice from a recording someone supplied is refused unless consent is confirmed — when it is added, and again when a package brings it in.
This website
Static pages over HTTPS with a strict content security policy: no scripts, no third-party resources, no cookies.
Last updated 28 September 2026.