Security
Every tunnel runs over TLS 1.3, end to end, with a certificate issued for that exact hostname. Tunnel keys are generated and held on your device; we never see or store them. The dashboard and API are served under a strict content security policy that allows no inline script or style.
If you believe you have found a security vulnerability in 127ohoh1, please email security@127ohoh1.com. Include steps to reproduce and the impact. Please do not access, modify or exfiltrate data that is not yours, and do not test against other customers' endpoints without their consent. We will acknowledge your report and follow up as we investigate.