Security Model
How Tactic Remote's security boundaries work across devices, network, and runtime.
Tactic Remote connects two trust zones -- the host machine (Mac/Windows) where code executes, and the mobile client (iPhone) where you control it. Understanding these boundaries helps you make informed decisions.
Architecture
The iPhone never talks to Claude's API directly. It sends commands to your Mac server, which manages the Claude Code process locally.
Trust zones
Host machine (Mac/Windows)
This is where Claude Code runs, reads your files, and executes commands. It is the highest-sensitivity component.
Your responsibilities:
- Keep the OS and Claude Code updated.
- Run the server under your user account (not root).
- Lock the machine when unattended.
Mobile client (iPhone)
The iPhone is a remote control. It sends text prompts and receives terminal output. It does not have direct file system access.
Your responsibilities:
- Use device lock / biometrics.
- Keep the app updated.
- Don't send destructive commands without verifying the active session path.
Transport (network)
- Local mode: unencrypted WebSocket (
ws://) on your LAN. Suitable for trusted networks. - Tunnel mode: encrypted WebSocket (
wss://) through Cloudflare. Suitable for public networks.
Credentials
Treat these as secrets:
- Server API key
- Cloudflare tunnel credentials
- Anthropic API key (managed by Claude Code)
What the server protects against
| Threat | Mitigation |
|---|---|
| Unauthorized connections | API key authentication |
| Command injection via session names | Input validation (alphanumeric only) |
| Path traversal | Path restriction + blocked sensitive dirs |
| Request flooding | Rate limiting (30/min) |
| Stale sessions after disconnect | tmux cleanup + heartbeat monitoring |
What the server does NOT protect against
- A compromised Mac (if someone has shell access to your Mac, the server offers no additional protection).
- Prompts that instruct Claude Code to do harmful things (Claude Code has its own safety mechanisms, but you should still review what you ask).
- Leaked API keys (rotate immediately if exposed).
Recommendations
- Default to local mode. Only use tunnel when you genuinely need remote access.
- Always set an API key for tunnel connections.
- Narrow the allowed path to your project directories.
- Review the active session path before starting high-impact tasks.
- Rotate keys when team members leave or after any suspected exposure.