Skip to content

Security: Streamize-llc/doan

Security

SECURITY.md

Security

Doan runs a server on your machine that feeds a Claude Code session, so whatever reaches it can reach the session as a prompt. The canvas only accepts WebSocket connections from its own page on localhost, with a per-process token; the team server stores only hashes of tokens and sessions.

If you find a way around that, or any other vulnerability, please report it privately through GitHub's private vulnerability reporting instead of opening an issue. We'll answer within a few days and credit you in the fix unless you'd rather not be named.

There aren't any published security advisories