How we keep your clients safe

A module that runs inside your game client must not be a way in. These are the rules it follows.

Signed code only

Every script your clients run is signed with a key that never touches our servers. If someone broke into our server, your clients would refuse their code.

Your own code, approved by you

Custom functions you write run only after you approve each change once, in the game. Nobody can swap them behind your back.

No password, no remote control

We never ask for your game password. The website sends commands; it never logs in as you. Revoke a client and it stops at once.

Open protocol

The module, the upload script and the API are public and MIT-licensed. Read every line before you install it.

What signing means for you

The module on your computer only receives scripts and runs them, so it never needs an update. Every script carries a signature made with our release key. That key lives offline, not on any server. The module checks the signature before it runs anything.

So even if someone broke into our servers, they could not send code to your client. The worst they could do is send a script we already signed and released.

Your own functions

When you write a custom function, the client shows it to you once, in the game, and runs it only after you approve it. A changed function needs a new approval.

What the website can do

It sends named commands, like pause or load route, and gets back what the client reports. It never sees your game password and cannot log in as you.

Check it yourself

The module, the upload script and the feed API are public: read them in the developer pages.