18 lines
992 B
Markdown
18 lines
992 B
Markdown
# Privacy and security
|
|
|
|
Descriptions and exchanges remain in memory and are never transmitted or
|
|
persisted. All remote/absolute `$ref` forms fail closed. Displayed URLs, broker
|
|
hosts, channel addresses, protocol bindings, and generated commands are text,
|
|
not live controls. There is no Try It button, broker connection, subscription,
|
|
publish action, OAuth flow, DNS lookup, HTTP execution, telemetry, or external
|
|
asset.
|
|
|
|
HAR and saved exchanges commonly contain tokens, cookies, personal data and
|
|
payloads. Header and cookie values may be used transiently to check parameter
|
|
presence and shape, and JSON bodies may be parsed for local schema checks, but
|
|
the summary and contract report never retain or render those values. The source
|
|
editor still contains the original capture; clear it before sharing. Generated
|
|
examples are heuristic and must not be treated as valid production data.
|
|
Validation and compatibility checks cover a useful bounded subset, not every
|
|
OpenAPI or JSON Schema rule.
|