Skip to content
TaktSignal

Security · Community Alpha

Security

What TaktSignal does to keep your ERPNext and your factory data safe, what it does not do yet, and how to tell us about a problem. Factual, including the gaps.

Last updated: 2026-09-26

Report a vulnerability

Please report suspected vulnerabilities privately to work.manhcang@gmail.com — not in a public issue or forum.

Include the TaktSignal version, your operating system, what an attacker could achieve and how to reproduce it — ideally with synthetic data.

  • Do not send real factory data: no ERPNext or TaktSignal backups, database dumps, or customer, supplier or order data.
  • Do not send or publish credentials: no API keys, secrets, passwords or session tokens.

We acknowledge reports as soon as we can (target: five working days), keep you informed, and prefer coordinated disclosure: please give us reasonable time — normally up to 90 days — to ship a fix before publishing details. We credit reporters who want to be credited. We will not take action against good-faith research on your own installation and your own or a test ERPNext. There is no bug bounty.

Dedicated read-only ERPNext account

TaktSignal connects with its own ERPNext user, the TaktSignal Reader, which has Read permission only. TaktSignal refuses the Administrator account. During setup it asks ERPNext for the Reader's permissions on real Sales Order, Work Order, Purchase Order, Bin and Item documents and stops if ERPNext reports any write, create, submit, cancel, amend or delete permission; the system check repeats this later. The check samples the document types TaktSignal reads, so give the Reader only the TaktSignal Reader role. Reader guide.

No ERPNext write behaviour

TaktSignal's ERPNext client only sends GET requests to the standard REST API, plus two read-only methods (version and permission lookup); anything else is refused before a request is made. It does not follow redirects, refuses plain HTTP to public addresses and cloud-metadata or link-local addresses, and never ignores TLS certificate errors. It never creates, submits, amends, cancels or deletes ERPNext documents.

Local PostgreSQL and loopback-only services

The desktop build runs for one operating-system user. Its PostgreSQL database, the TaktSignal application and the Control Center listen only on 127.0.0.1 — nobody else on the network can connect. The database accepts only TaktSignal's own account from 127.0.0.1 with a random password. The data folder is readable only by your user (0700). The Control Center opens through a one-time link and rejects cross-site and DNS-rebinding requests.

Credential storage in the operating system

ERPNext API credentials and the database password are stored in the OS credential store: macOS Keychain, Windows DPAPI (current user), Linux Secret Service. If no secure store is available, setup stops rather than writing secrets to a file. Credentials reach TaktSignal's own processes through their environment, never through command lines, and never appear in the interface, logs, backups or diagnostics.

Download and update integrity

Release metadata — versions, file sizes and SHA-256 checksums — is signed with an Ed25519 release key. This website shows a download only when that signature verifies, and the installed app installs an update only when the signature, the download host, the size, the SHA-256 and the checksum of every file inside the update all match. Updates are never automatic, never downgrade, and roll back if the new version does not start. Verify a download yourself.

Diagnostics redaction

The diagnostics file contains versions, health and counts. Company, site and user identifiers are replaced by keyed hashes whose key is discarded. Before writing, TaktSignal scans the file for every secret it holds, the ERPNext host, the home folder path and every company, customer, supplier, item, user and document name it knows; one match and no file is written.

Privacy model

No telemetry, analytics, crash-reporting service or remote logging. Outbound connections: your ERPNext, and the TaktSignal release server only when you check for or install an update. Details in the privacy policy.

What is not in place yet

  • No code signing. The macOS app is not signed with an Apple Developer ID or notarized; the Windows installer is not Authenticode-signed. Integrity relies on the signed release metadata and checksums.
  • No external audit. TaktSignal has not had a third-party security audit or penetration test and holds no security certification (no SOC 2, no ISO 27001).
  • Same-user access. Anyone who can log in as your user on the computer can reach TaktSignal's local services and data. Use a computer account only you use.
  • Alpha software. Security-relevant defects are possible. Keep TaktSignal updated and connect a staging copy of ERPNext first.