Security Do not commit API keys, Wi-Fi credentials, hardware secrets, or model-provider credentials. Hardware mode is disabled by default and must be explicitly selected by an operator. The browser must not call secret-bearing model APIs directly. Treat generated reports and exported telemetry as potentially sensitive demo data. Report security issues privately to the project owner before public disclosure.