This is experimental numbers-station research/education software. It is not a certified emergency system. Users are responsible for their hardware, software modifications, transmitted content and applicable operating rules. See LICENSES.md and the license texts for warranty/liability terms.
- Traffic is unencrypted; station IDs are not authenticated. CRC and SHA-256 detect damaged/inconsistent transfers, not a malicious authenticated peer.
- Received files can contain hostile data. The station saves them and does not execute or open them automatically. Inspect them before opening elsewhere.
- The Flask panel is intended for localhost on the station computer. Its session token, host/origin checks and CSP are not a public multi-user service. Do not expose its control port to the internet or remove these checks casually.
- Runtime data contains plaintext messages/files and device settings. Keep it out of repositories and screenshots. Back it up and protect access yourself.
- A dictionary substitution is not encryption. Do not claim it supplies secrecy, authentication, one-time-pad security or resistance to analysis.
- Hardware PTT, volume and microphone controls remain outside the software. A stopped player cannot recall transmitted audio or release a manual PTT.
Use the repository's Security → Report a vulnerability private reporting form: private report. Include the affected commit, OS/dependencies, minimal reproduction and impact. Avoid sending private recordings, credentials, real station traffic or unnecessary exploit payloads. If private reporting is unavailable, open an issue requesting a private contact channel without disclosing the vulnerability. No response time or security support period is guaranteed.
For ordinary decoder/audio problems, use a normal bug report with fictional reproduction data and make clear whether it used physical hardware or a WAV.