Security dossier

What Fictor protects—and what it does not.

Private source is not a security claim. These are the actual boundaries of the alpha, including the uncomfortable parts.

Short version: Fictor treats model output as untrusted text. The model receives no shell, host tools, or filesystem access. Candidate code runs in Chrome’s sandbox behind a restrictive Content Security Policy. The Build path is not additionally confined by a Linux kernel sandbox.

Model boundary

Candidate and delivery boundary

Local control plane

The application listens on 127.0.0.1 by default. A user can deliberately bind it to another interface, but doing so exposes it to that network and changes the threat model.

Network and data behavior

Known limitations

Release transparency

Each public release is intended to include SHA-256 checksums, a CycloneDX SBOM, third-party licence texts, the applicable Fictor licence, privacy terms, and release limitations. The product source remains proprietary. The three small runtime files embedded in generated applications are licensed under 0BSD so users can distribute their own applications.

Report a vulnerability

Email security@fictor.dev. We target acknowledgement within five working days. There is no bounty program.

We will not initiate legal action against research conducted in good faith under our policy: avoid harm, disruption, and unnecessary access to personal data; access only what is needed to demonstrate the issue; stop and report if sensitive data is encountered; do not exploit the issue or use threats; and allow a reasonable opportunity to respond before public disclosure. This does not authorize unlawful access or bind third parties.

Do not send a complete Fictor run directory. It can contain your brief and generated source. Inspect and redact every artifact before sending it privately.