Please do not open a public issue for security problems. Use GitHub's private reporting instead: open the repository's Security tab and choose Report a vulnerability. You will get a reply there.
- The keyboard, over USB raw HID (read events, set layers and LEDs, flash firmware when you ask).
- The Mac's built-in keyboard, only with the guard on, through the system
hidutiltool (no root, no kernel extension). - Two network endpoints, both read-only:
oryx.zsa.iofor your layout, andapi.github.comfor the latest release tag. There is no telemetry. - Files under
~/Library/Application Support/keyjitsu/and, with start-at-login on, one LaunchAgent plist in~/Library/LaunchAgents/.
Only the latest release gets fixes.