Trust model

Your host stays authoritative.

Drover gives an iPhone permission to control a live Herdr session. It does not take custody of your workspace, source code, or host credentials.

01

Local authority

Agents and terminal sessions remain on your macOS or Linux host.

02

Cryptographic pairing

Pairing keys identify devices; no Drover account is required in v1.

03

Fail closed

No connection means no input, no offline command queue, and no ambiguous retry.

What each system can observe

Your iPhone
The paired host identity, session state, terminal-backed content required for the UI, and supported control responses.
Your host
The paired device identity, live Herdr state, and commands that arrive over the authenticated encrypted session.
Cloudflare signaling
Opaque routing identifiers, public endpoints, timing, and encrypted signaling messages. It does not receive plaintext terminal content.
Cloudflare TURN
Network metadata and encrypted traffic when direct connectivity fails. The relayed payload remains end-to-end encrypted.
Push service
A generic wake hint and minimum opaque route metadata—never commands, paths, hostnames, or terminal output.

Non-negotiable controls

  • Verified hostname: Drover displays the real verified hostname; a nickname never visually replaces it.
  • Authoritative decisions: Approve or deny controls may be shown only for a structured request with an exact response path.
  • No host push secrets: APNs provider credentials remain in Cloudflare Secrets and are never installed on your machine.
  • No queued input: Drover does not store commands to run after a reconnect.
  • No automatic ambiguous retry: a command with uncertain delivery is not silently repeated.

Pairing and revocation

Initial pairing happens over the local network with a short-lived QR invitation. The phone and host show a matching human-readable verification phrase. Paired-device credentials can be revoked without creating a Drover account.

Report a security issue

Email admin@newdrover.com with a clear description, affected version, and reproduction steps. Do not include active credentials, pairing secrets, private source code, or production tokens.

For data practices, read the privacy policy.

Evaluate Drover before you install.

Join beta updates for release notes, compatibility details, and signed installation access.

Join beta updates