Security and local data
Hamen Markup 1.x resolves document resources inside an explicit project root. It does not execute arbitrary Python or JavaScript from source documents, fetch remote imports, or submit forms to a remote service. Links can open external URLs when a reader follows them. Custom documents can include local resources, so review unfamiliar source before compiling it and choose the smallest useful project root.
The editor and preview server bind to loopback. They are development/authoring tools, not authenticated multi-user services; do not expose them through a public proxy. Compilation has bounded source sizes, expression work, nesting, and expansion, but is not a hardened multi-tenant service boundary. Run untrusted bulk jobs in an isolated operating-system environment with CPU, memory, time, and filesystem limits.
Browser drafts live in local browser storage. Saved notes remain plain files. Hamen Markup does not add cloud backup, encryption, or synchronization. Back up important source files with your existing system.
Report suspected vulnerabilities privately using the contact route at https://hamen.dev/support. Include the compiler version, operating system, a minimal reproducer, and expected versus observed behavior. Do not include private notes or credentials. Security fixes are issued for the latest stable 1.x release; update older installations before requesting support.