No data leaves the device
Layouts, media and settings are stored in the app's own storage. There is no upload, no sync and no backup to anywhere we control.
Security
A product with no cloud has a different security shape from one with a cloud. This page describes it plainly, including the parts that need care.
Layouts, media and settings are stored in the app's own storage. There is no upload, no sync and no backup to anywhere we control.
No analytics SDK, no crash reporter phoning home, no usage beacon. The app does not know we exist.
Nothing to breach, because there is no credential store, no tenant and no user database.
Be aware
Two honest properties of the design, and how to handle them.
The admin console runs on port 8080 over HTTP on the local network. That is a deliberate trade for zero configuration — no certificate to provision on a device that may never see the internet — and it means the network, not TLS, is your boundary.
The kiosk lockdown works without an MDM and without device-owner provisioning, which is what makes it deployable by a shop or a school. The cost is that the operating system is not enforcing it:
Mitigate physically: an enclosure, USB debugging off, and a covered port. If your threat model needs OS-level enforcement, provision the device as device owner through an MDM and run UniKiosk as the board on top.
Reporting
Email hello@unikiosk.io with the version, the device, and enough detail to reproduce it. We will confirm receipt and tell you what we intend to do about it.
Please give us a reasonable window before publishing. We do not run a bounty programme and will not pretend otherwise, but we will credit you if you want to be credited.
There is no hosted service to attack, so the interesting surface is the on-device HTTP server, the layout import path and the lockdown itself.
Network, enclosure, updates and the failure modes worth rehearsing before you leave site.