Appearance
Security Practices
Protect secrets
- Never share recovery phrases, private keys, cookies, license documents, provider credentials, configuration files, wallet files, or logs.
- Use encrypted backups and keep configuration with its paired local key material.
- Verify addresses and contract identity independently before approval.
- Keep Windows, Sthang, and your security software current.
Treat external data as untrusted
Collection metadata, marketplace listings, provider responses, external links, and release notes can all be wrong or malicious. Sthang reduces and validates what it displays, but the operator still owns the final approval.
Verify distribution
Use only the controlled installer link sent by the Sthang owner. In-app updates require private device enrollment and are verified with a dedicated updater public key embedded in Sthang. The updater key and OTA access credential are separate from licensing, wallets, and transaction signing.
The initial release is not Authenticode-signed, so Windows may show a new-publisher SmartScreen warning. A SmartScreen warning does not replace source verification, and bypassing SmartScreen globally is not recommended.
Respond to uncertainty
Stop when a result is ambiguous, a review becomes stale, or a submitted transaction lacks clear evidence. Preserve the current data directories, attempt history, and duplicate-prevention records. Do not erase evidence or create a replacement submission until the original outcome is resolved independently.

