Safety by design
A useful toolbelt needs clear boundaries.
Detour will handle private development context. These are the checks we need to pass before calling the local app or future sharing flow ready.
Current state: early local build. This is a release checklist, not a security certification.
Software boundary
- Keep the web UI and MCP endpoint on the local host; reject unexpected hosts and browser origins.
- Run the container without root privileges, extra capabilities, or broad host mounts.
- Make SQL, file, and test tools opt-in, scoped, and stoppable. Ask before destructive actions.
- Validate API and MCP inputs, paths, queries, file sizes, and tool outputs.
- Pin and scan dependencies and base images before each release.
Your data
- Store records in a persistent local volume and keep secrets out of logs and exports.
- Preview every export and include only the selected records; test round-trip import.
- Back up and restore the SQLite volume, including a real recovery test.
- Make deletion and archive behavior clear; verify no hidden data remains in exports.
- For future links, require sign-in, short expiry, revocation, and download limits.
Release gate
Prove it before we promise it.
Security tests, export and restore tests, a clean dependency scan, and a reviewed threat model should be recorded for each release. The detailed checklist lives in the project docs.