Experimental Alpha

How Rovarin security and remote access work

Rovarin runs on your Windows PC. It authenticates dashboard access with a PIN and relies on Tailscale to create the private network path between your devices.

Important: Rovarin does not claim to provide its own end-to-end encrypted network. Tailscale supplies the private connectivity, and its security properties are governed by Tailscale.

Access is authenticated

Phone and ordinary browser access require the Rovarin PIN. Successful authentication creates a bounded session rather than sending the PIN with every dashboard request. Repeated failed attempts are rate-limited, and regenerating the PIN invalidates existing sessions.

Configuration stays local

Rovarin stores its configuration on the Windows PC and protects sensitive local configuration for the current Windows user. It does not require an account with a Rovarin cloud service and does not upload PC telemetry to a Rovarin-hosted dashboard.

Tailscale provides remote connectivity

Rovarin accepts supported local connections and private Tailscale connections. For access away from home, Tailscale must be installed and Connected on both the PC and the phone or browser device. Rovarin does not enable Tailscale, change its account, or create a proprietary relay network.

Remote actions are constrained

Rovarin exposes specific implemented operations. Process termination checks that the selected process is still the one observed by the dashboard and protects Rovarin and Windows system processes. Maintenance controls are allowlisted actions. Rovarin does not provide an arbitrary remote shell or command-execution field.

Updates are verified

The updater accepts a specifically named release installer and verifies its size and SHA-256 checksum before opening it. Installation begins only after the user continues through the Windows installer. A checksum verifies file integrity; it is not the same as a code-signing certificate.

What users still control

  • Keep Windows, Rovarin and Tailscale updated.
  • Keep the Rovarin PIN private and regenerate it if exposed.
  • Review installer provenance and the published checksum.
  • Do not disable Windows security protections to install Rovarin.
  • Disconnect Tailscale when you do not want remote network access.

Report a vulnerability privately

Avoid posting PINs, private addresses or security details in a public issue. Use GitHub private vulnerability reporting.