How we keep your clients safe
A module that runs inside your game client must not be a way in. These are the rules it follows.
Signed code only
Every script your clients run is signed with a key that never touches our servers. If someone broke into our server, your clients would refuse their code.
Your own code, approved by you
Custom functions you write run only after you approve each change once, in the game. Nobody can swap them behind your back.
No password, no remote control
We never ask for your game password. The website sends commands; it never logs in as you. Revoke a client and it stops at once.
Open protocol
The module, the upload script and the API are public and MIT-licensed. Read every line before you install it.
What signing means for you
The module on your computer only receives scripts and runs them, so it never needs an update. Every script carries a signature made with our release key. That key lives offline, not on any server. The module checks the signature before it runs anything.
So even if someone broke into our servers, they could not send code to your client. The worst they could do is send a script we already signed and released.
Your own functions
When you write a custom function, the client shows it to you once, in the game, and runs it only after you approve it. A changed function needs a new approval.
What the website can do
It sends named commands, like pause or load route, and gets back what the client reports. It never sees your game password and cannot log in as you.
Check it yourself
The module, the upload script and the feed API are public: read them in the developer pages.