Hatrack is intended to run on trusted local networks or behind an authentication/reverse-proxy layer.
The built-in admin panel and API can edit routing state and backend URLs. Do not expose a Hatrack instance directly to the public internet without adding access control.
This public repository contains sanitized example defaults only. It should not contain private hostnames, private network names, LAN IPs, API keys, model paths, runtime state, or decision logs.
If you find a security issue, please open a private GitHub security advisory or contact the maintainer through GitHub.