Security
How Captain Relay is designed to control remote access safely.
Security model
- Authenticated access before private remote operations.
- Server-side device ownership and tenant scoping.
- Exact remote-tool discovery before execution.
- Server-enforced allow, deny and human-approval policies.
- Persistent jobs with attributable status/results.
- Device/session revocation and audit records.
- Fail-closed host routing between app, API, MCP and installer surfaces.
Payment security
Payment credentials are intended to be collected through secure payment-provider components rather than stored by Captain Relay application servers.
Vulnerability disclosure
Email cybercrime@zebrabyte.co.uk with the affected component, reproduction steps and impact. Do not access other customers' data, persist on systems or degrade availability.