SpeakTrue

Web and iOS Security Remediation

Date: 2026-09-04

Outcome: security remediation and the full per-user legacy Soundboard action migration are implemented and locally verified. The approved existing per-user Supabase tables are authoritative for categories and clips in every storage adapter mode. Historical shared data has not been reassigned or imported. Deployment, physical-device proof, recording provenance, and residual hardening remain outstanding. This is not an all-clear security certification.

Base: d88346208a855294f85050b7105896b89b2f9a18, including the existing uncommitted web transcription and iOS Local Qwen prototypes.

This work follows the August 31 web/iOS audit. Native Daybreak contributors implement the web and iOS changes; the primary Codex agent reviews and verifies integration. Changes require verification before any deployment claim.

Recording provenance and packaging

Four voice-sample M4A files remain tracked under web/python-web-app/static/uploads/. Existing repository documentation calls them user-supplied voice sample fixtures. Their identity, consent, and intended retention have not been established by this audit. File names and durations alone do not establish a privacy breach, and the previously tested deployment paths returned 404.

The Docker build already excludes uploads, speech, and cache directories. Git ignores now cover all three runtime directories, including metadata and non-MP3 formats. The dev deployment rsync excludes those directories and the last-input text file; these exclusions also preserve destination-only runtime data during deployment. Neither ignoring nor excluding a file removes it from Git history or existing clones.

Provenance review and any coordinated history removal remain outstanding. Do not copy the recordings into documentation or replace them with newly collected personal audio. Tests should use generated synthetic content.

Verification and rollout

Implemented controls

Validation evidence

Reproducible commands:

web/python-web-app/venv/bin/python -m pytest -q -o addopts='' web/python-web-app/tests
web/python-web-app/venv/bin/python -m pip check
xcodebuild -project ios/SpeakTrue.xcodeproj -scheme SpeakTrue \
  -destination 'platform=iOS Simulator,id=3DD20D4B-A7FB-4FF7-9D16-2D89A688DAF9' \
  -derivedDataPath /private/tmp/speaktrue-security-audit-derived \
  -clonedSourcePackagesDirPath /private/tmp/speaktrue-security-audit-sourcepackages \
  -skipPackagePluginValidation CODE_SIGNING_ALLOWED=NO test \
  -only-testing:SpeakTrueTests
git diff --check

The simulator identifier is environment-specific. The primary Xcode rerun first failed on sandbox cache access, then passed with approved Xcode/simulator access. The local Python test environment now contains both updated dependency pins; pip check reports no broken requirements.

Remaining boundaries and rollout prerequisites

Change accounting

Changes remain uncommitted on main at the stated base. No push or deployment. Pre-existing user changes to prototype/provider work, package resolution, guides, demo artifacts, and research were preserved.