Podium can run commands, read repositories, and relay terminal input on paired machines. Treat server access, machine pairing, state backups, and agent approvals as privileged operations.
Keep the server boundary small
Prefer a private Tailscale route for remote access. If you expose Podium publicly, require authentication and Transport Layer Security (TLS) through a stable reverse proxy or supported tunnel.
The daemon initiates its connection to the server. Remote execution machines do not need public inbound ports.
Protect machine pairing
Join codes embed the server address and a one-time pairing credential. They expire after one hour. Share them only through a trusted channel.
During pairing, Podium can copy guarded native Claude Code and Codex credentials from an online machine owned by the same user. This occurs only when credential copying is enabled for the pairing grant. Review the target machine and its operators before enabling it.
Know what Podium stores
The state directory contains the SQLite database, configuration, logs, uploads, transcript mirrors, issue artifacts, machine identity, pairing tokens, and server-managed secrets. Agent harnesses keep additional state in their own home directories, such as ~/.claude or ~/.codex.
Issue artifacts are immutable snapshots independent of their source files. Deleting or changing a source file does not change its stored snapshot, but removing the artifact through Podium deletes the server-side copy.
Protect the applicable state root and its backups with the same controls as your source repositories and agent credentials.
Review agent actions
Agent-session lifecycle commands and automation requests may require operator approval. Check the exact command, target, and path before approving them.
Podium does not make generated commands safe. Harnesses run with the permissions of their host account.
Control self-hosted telemetry
Local and self-hosted usage and crash telemetry are off unless you opt in. Inspect the current state and exact queued payloads:
Disable both tiers at any time:
DO_NOT_TRACK=1 or PODIUM_TELEMETRY=off suppresses this self-hosted telemetry even when stored consent says on. The local Pulse usage view and harness quota display are separate from hosted billing or metering.
Hosted analytics are a separate path and are not controlled by these self-hosted settings. When the corresponding deployment keys are configured, the hosted browser shell initializes PostHog with exception capture and session recording configured to mask all text and inputs. The hosted API reports login, machine connection, session, completed turn, issue creation, and client crash events. Those events can include opaque user, machine, session, issue, and instance identifiers, harness kind, client version, and crash type and message. The API integration intentionally excludes issue titles, session names, prompts, transcripts, and crash snapshots.
Understand marketing website analytics
The public marketing page at podium.do/ uses Google Analytics 4 to measure visits. Its Google tag sends page activity and browser and device information to Google, which also derives approximate location. Google Analytics uses first-party _ga and _ga_* cookies to distinguish visitors and sessions. This is separate from the self-hosted telemetry controls and the hosted application’s PostHog analytics described above.
You can block or delete these cookies in your browser, or use the Google Analytics opt-out browser add-on. Google explains how it uses information from sites that use its services.
Report vulnerabilities privately
Follow the private reporting instructions in the Podium security policy. Do not open a public issue with exploit details or credentials.
The hosted application currently sends Content Security Policy in report-only mode. Browsers can surface violations, but the policy does not block them and the reviewed code does not configure a server-side report collector. Do not describe it as enforced browser isolation.