SecuritySecurity designed around a live session
AirDows protects the connection, limits access to each room, and keeps file contents out of operational metrics.
Last updated: July 19, 2026
Current protections
Temporary codes
Unused rooms expire after three minutes and accept only the devices required for pairing.
Encrypted traffic
WebRTC encrypts data while it travels directly or through the TURN relay route.
Abuse prevention
The server limits requests, pairing attempts, and free relay usage.
Protected administration
The internal dashboard requires a private token and is not linked from the public application.
Current limitations
- No internet-connected service can promise absolute security.
- AirDows has not yet published an independent security audit.
- Transfer speed and reliability depend on browsers, devices, and network routes.
- Mobile systems may pause a browser tab when the screen is locked or the app enters the background.
- Bluetooth file transfer is not available from the web app because browser support is inconsistent.
Use AirDows safely
- Verify that the QR code or PIN belongs to the device you intend to connect.
- Do not publish pairing codes or share them with strangers.
- Keep both devices visible and active during a transfer.
- Cancel the session if an unfamiliar connection appears.
- Keep your browser and operating system up to date.
Responsible disclosure
If you find a vulnerability, email saocampoe@unal.edu.co. Include reproduction steps and avoid publishing details that could put users at risk before the issue can be reviewed.
Do not include personal files, active pairing codes, or credentials. A short description, browser version, and reproduction steps are usually enough.
Understand the complete route
See what each server does and when it is used.
See how it works