Remote security
Experimental
- Default to loopback whenever possible.
- Do not expose the server directly to the public internet.
- Use trusted networking, VPN/tunnel, or TLS reverse proxy for remote access.
- Use strong authentication when your deployment enables it.
- Treat API keys and server passwords as secrets.
- There is no custom BotConnector encrypted pairing protocol promised by the current public CLI.