Security

Privacy & security model

Understand what MediaHub Management stores, what stays on devices and what managed hiding can and cannot guarantee.

Direct media connections

MediaHub Management is a configuration/control plane. It does not sit in the media path. IPTV, EPG, Jellyfin, Emby, Plex and VPN traffic connect directly from the user's MediaHub device to the configured service.

IPTV credentials

The Management panel does not need the end user's IPTV username/password for the managed login flow. Those credentials are entered into MediaHub on the device.

Hidden configuration is not cryptographic secrecy

Managed deployments intentionally remove provider and Management addresses from ordinary user-facing screens where possible. However, the app must still know where to connect. A determined person may discover endpoints through reverse engineering or network inspection.

Signing identity

Never distribute the official MediaHub private signing key. Each Management customer should create, secure and back up their own Android signing identity.

HTTPS

Use a stable HTTPS hostname for public Management deployments before distributing managed apps.