The Connector is built to expose as little as possible.

  • It makes one outgoing, encrypted connection to Seedr on TCP port 443. No port forwarding and no public IP address.

  • Seedr never gets your NAS password.

  • Seedr sees only the folders you list in config.json. You can make each folder read-only.

  • It runs as the owner of your NAS share, not as root. It needs no privileged mode, no published ports and no Docker socket.

  • You can revoke access at any time. It takes effect within seconds, even during a transfer.