Skip to main content
Liiiraa Boost
Menu
Security

Security and Trust

Learn the technical boundaries planned to protect the site, future account, artifacts, and Windows changes, together with the rules for coordinating a vulnerability report after preflight.

Current version
2.0.0
Effective date
Accountable contact
security@liiiraa.com

Local-first trust model

Diagnostics, plans, measurements, history, and restoration stay on the PC by default. The web receives no authority to deeply inspect the machine or execute optimizations. Any diagnostic leaving the device requires specific review and authorization; cloud AI and optional telemetry remain separate from essential features.

Least privilege on Windows

The desktop interface does not keep permanent administrator privilege. Elevated actions must pass through an isolated, authenticated component limited to specific operations with validated parameters, a known consequence, and a record. We do not accept arbitrary remote scripts or general-purpose registry, file, or service commands. Missing compatibility or safe recovery blocks the action.

Plans, history, and restoration

Persistent changes must show scope, risk, dependencies, and restart needs before confirmation. Execution records what was requested, applied, skipped, or reverted. Competitive Mode temporary actions preserve prior state and seek to restore it when the session ends. History and restoration remain available on Free and after subscription expiration.

Verifiable installer and update chain

Public distribution begins only when publisher, signature, SHA-256, version, channel, compatibility, artifact, and manifest agree. A discrepancy or invalid signature blocks installation and update; there is no continue-anyway option. Manifests and packages are immutable per version, channels have their own policy, and a security rollback cannot install an untrusted artifact.

Account, device, and administration

When accounts and authentication are activated, sessions will use minimum storage, anti-forgery protection, expiration, and revocation; passkeys and MFA may increase protection without exposing a reusable secret. The approved design uses derived, protected device identity rather than raw HWID. Administration will remain on a separate origin, session, roles, and policy with least privilege, sensitive-action confirmation, and an audit trail.

Data, secrets, and support

Credentials, tokens, keys, and payment data must not appear in URLs, telemetry, logs, or support packages. If diagnostic upload is activated, the package will be reviewable, minimized, and tied to a case. Internal access will need to be justified, authenticated, and recorded; retention will end with the purpose or applicable duty. Processors and transfers will be identified before they receive data.

Development and vulnerability response

Input contracts are validated at implemented boundaries; dependencies, permissions, and infrastructure changes receive risk-appropriate review and tests. When response operations are activated, a confirmed flaw will be triaged by impact and exploitability, remediated with safe recovery, and communicated without details that increase risk. Personal-data incidents will follow applicable assessment and notice duties.

How you help protect access

Use official installers, check integrity warnings, keep supported Windows and application versions, protect email and authentication factors, and do not share a session. Review a plan before applying and do not ignore compatibility, anti-cheat, or restart warnings. If you suspect compromise, artifact mismatch, or an unexpected change, stop, preserve minimum evidence, and contact support or security@liiiraa.com.

Vulnerabilities and incidents

The Responsible Disclosure Policy defines assets, allowed testing, prohibited conduct, and a designated contact whose operation depends on preflight. Reports must avoid personal data and access beyond the minimum. There is no automatic reward. If an incident affects users, communication will prioritize what happened, known impact, protection, and recovery without claiming certainty before the investigation.

Limits of this statement

No system is infallible. Liiiraa Boost does not claim ISO 27001, SOC 2, certification, an independent audit, a protection percentage, manufacturer approval, or an absolute absence of vulnerabilities. Good-practice references guide design, but only implementation and verifiable evidence demonstrate a control. Mandatory consumer rights and warranties remain preserved.

Version history

  1. 1.0.0

    Initial statement of security boundaries and Windows operations.

  2. 1.1.0

    First detailed description of authority, recovery, integrity, and response.

  3. 2.0.0

    Final pre-launch statement covering local-first, least privilege, update chain, accounts, data, response, and assurance boundaries.