Short-lived and bounded

Security

Pairing uses independent cryptographic tokens and human-friendly codes, strict expiry, one-peer enforcement and rate limits. Internet workloads are time, body and concurrency bounded.

Pairing protection

Tokens contain 256 bits of randomness. Codes contain 40 bits, exclude ambiguous characters and are protected by join throttling. Redis keys are HMAC-derived.

No TURN in local mode

No relay service is configured. Candidate evidence is checked on both peers, and an unverified path cannot produce a LAN speed result.

Report a concern

Do not include pairing tokens, private IP addresses or sensitive network information in a report. Use the contact page to reach the operator.