POCKETPILOT SECURITY GUIDE Updated 10 September 2026 LOCAL WI-FI A paired device can control the Windows session. Use local Wi-Fi mode only on trusted Private networks. Never forward router port 8787, publish the setup page or pairing code, or allow a public inbound firewall rule. Anywhere does not require one either. Local pairing uses a rotating, single-use six-digit code and creates an HttpOnly, SameSite session cookie. Stored local tokens are SHA-256 hashes. PocketPilot does not store Windows passwords, PINs or Hello secrets. The companion accepts only fixed media, app, pointer, display and power actions, not arbitrary scripts or commands. Public-source addresses, unknown hostnames, cross-origin command requests and oversized/unknown fields are rejected by the local service. Windows lock, UAC secure desktop and Windows Hello stay protected. POCKETPILOT: ANYWHERE — INCLUDED WITH PREMIUM Available to every Premium user with PocketPilot 1.4.0 or later. Choose Anywhere in the Overview address dropdown, read the notice, and enable it. Premium is verified automatically; no registration file is required. Choose permissions, create a QR code, scan privately, compare fingerprints on both devices and approve on Windows. Reject a mismatch. Do not publish QR links or registration files. No separate VPN or router port forwarding is required. Devices make outbound connections through the relay, which is not a general proxy and does not publish the local HTTP service. Controls and screen pictures are encrypted between devices with identity checks, replay protection and expiring credentials. The relay sees connection metadata rather than ordinary plaintext control content. Authorization stays on Windows, including live device permission and Premium checks. Local and Anywhere pairings are separate; a transport token alone does not authorize Windows commands. Fresh session keys provide forward secrecy: later theft of saved identity keys alone should not reveal earlier recorded session content. This applies to the updated protocol, not traffic from older releases. Old session keys are discarded when reconnecting. Independent security review is pending. A compromised PC, paired browser or hosted controller can expose access and content while in use. Do not treat PocketPilot as independently audited for sensitive systems. Keep the PC awake and online. Premium verification renews automatically; an extended verification outage, a stopped app, an expired phone token or an outage stops the connection. Tokens renew while connected; after more than 24 hours offline, a fresh QR may be needed. Reconnection uses a fresh encrypted session and does not replay input commands. There is no audio, file transfer, wake-from-offline, or protected Windows screen control. Browser keys are stored in that browser. Reopen the same browser; clearing storage or switching browsers requires pairing again. DEVICE ACCESS In Windows Devices, review permissions, rename, pause or remove a device. Removal also revokes its Anywhere relay access. Forget on a connected phone waits for Windows confirmation before clearing its pairing. If offline, remove it from Windows. Switching Anywhere off stops internet connections without deleting pairings; use removal to end access permanently. Keep registration files, pairing links and license keys out of public support. Setup: https://pocket-pilot.net/setup#anywhere-setup Data handling and deletion: https://pocket-pilot.net/privacy#anywhere Private support: https://pocket-pilot.net/support