Skip to content

Security and Privacy

Adam Greenwell edited this page Aug 11, 2026 · 2 revisions

Security and Privacy

Back to Home

Wayfindr handles support conversations, visitor context, attachments, and consented cobrowse data. Self-hosters control the infrastructure and are responsible for lawful use, access, retention, backups, notices, and deletion or export workflows.

Report a Vulnerability

Do not publish exploit details in an issue or pull request. Follow the security policy and use private vulnerability reporting.

Before Real Traffic

  • Use HTTPS and secure WebSocket routing.
  • Keep application, database, Redis, host packages, and images patched.
  • Keep Composer dependencies on the reviewed lock file; source installs should update with composer install from the release checkout rather than ad hoc dependency resolution.
  • Store secrets outside Git and avoid placing them in logs or issue reports.
  • Review account roles, site assignments, and platform-operator boundaries.
  • Configure attachment storage and malware scanning deliberately.
  • Set retention expectations and prove backup deletion behavior.
  • Use synthetic data for tests and support reproductions.

The repository remains authoritative for data responsibility, the data inventory, and cobrowse boundaries.

Clone this wiki locally