Repository navigation
Security and Privacy
Adam Greenwell edited this page Aug 11, 2026
·
2 revisions
Wayfindr handles support conversations, visitor context, attachments, and consented cobrowse data. Self-hosters control the infrastructure and are responsible for lawful use, access, retention, backups, notices, and deletion or export workflows.
Do not publish exploit details in an issue or pull request. Follow the security policy and use private vulnerability reporting.
- Use HTTPS and secure WebSocket routing.
- Keep application, database, Redis, host packages, and images patched.
- Keep Composer dependencies on the reviewed lock file; source installs should
update with
composer installfrom the release checkout rather than ad hoc dependency resolution. - Store secrets outside Git and avoid placing them in logs or issue reports.
- Review account roles, site assignments, and platform-operator boundaries.
- Configure attachment storage and malware scanning deliberately.
- Set retention expectations and prove backup deletion behavior.
- Use synthetic data for tests and support reproductions.
The repository remains authoritative for data responsibility, the data inventory, and cobrowse boundaries.