Security

Secure by design.
Honest about limits.

HomesteadWatch is built for private, self-hosted camera access. This page explains the project's security approach and how to report a vulnerability privately.

Last updated: 12 August 2026

Security approach

HomesteadWatch is being built around a small, self-hosted trust boundary. The application is intended to run on hardware controlled by the operator, with remote access provided through an appropriately secured private network rather than by exposing camera services directly to the public internet.

The Community Preview will not be presented as perfectly secure or universally hardened. Security depends on the HomesteadWatch release, the host operating system, the camera, supporting services, network policy, and the operator's configuration.

What the project is designed to avoid

  • No HomesteadWatch-operated cloud is required to carry users' camera footage.
  • No website account is required to read project information.
  • No advertising or behavioural tracking is built into this public website.
  • Secrets, camera credentials, private keys, and production configuration must not be included in public release packages.

Reporting a security issue

Please report suspected vulnerabilities privately first. homesteadwatch@proton.me Use a clear subject such as “HomesteadWatch Security Report”.

Please include enough detail to reproduce the issue, the HomesteadWatch version or commit if known, and the affected component. Do not send passwords, private keys, full credential-bearing RTSP URLs, or unrelated private camera footage.

Please do not test against systems, cameras, accounts, or infrastructure that you do not own or have explicit permission to test.

Community Preview expectations

Reports will be reviewed as time permits. The Community Preview does not include a guaranteed response time, security SLA, paid support entitlement, or promise that every environment can be supported.

Security fixes that materially affect users will be documented as clearly as practical in release information and project documentation.