Vigilia handles camera recordings and potentially sensitive notifications.
- Use an unguessable ntfy topic or an authenticated self-hosted ntfy server.
- Keep
~/.config/vigilia/vigilia.envreadable only by the account owner. - Do not expose Motion web-control or stream ports without authentication and network restrictions.
- Enable full-disk encryption and a strong screen-lock password.
- Follow applicable workplace, tenancy, privacy, and recording laws before monitoring shared spaces.
Security reports should avoid publishing private recordings, tokens, or topic names in public issues.