SECURITY
Security
AI transmission is designed around explicit action and fail-closed behavior.
Last updated: August 2, 2026
Safe initial state
- Launching alone captures nothing
- Meeting capture cannot start without participant and organization permission confirmation
- AI audio starts OFF in listen-only
- The physical microphone and AI gate are independent
- Kill immediately stops AI without dropping the microphone
Speak once
One-shot is available from both the GUI and local MCP. Meeting transmission does not open until AI audio actually begins. Start wait, silence grace, and maximum transmit time are bounded, and completion returns the path to OFF. Continuous transmission is separated into an advanced control and requires manual stop.
Stop and restore
MCP EOF, cancellation, Stop, and app termination close AI audio and destroy temporary taps and aggregate devices. If the app changed the default input, it restores the previous input when possible.
Drivers
Persistent public inputs are user-space AudioServerPlugIns, not kernel extensions. Initial installation and updates require administrator approval.
Application updates
Updates are verified against a pinned Ed25519 public key and must be Developer ID signed, Apple-notarized, and stapled before distribution. The app checks daily but never applies an update automatically; installation requires user action.
Report a vulnerability
For sensitive audio, gate, signing, or installer findings, do not post confidential details publicly. Email info@brainfiber.net with the subject “Viyv Meeting Bridge Security”.