top of page
Asset 42_4x.png

ConfigLatch Security

ConfigLatch is designed to help Roblox studios control live Experience Config changes and fail safely when authoritative state is unclear.

Official Roblox connection

ConfigLatch connects using official Roblox OAuth and Open Cloud.

ConfigLatch does not ask for your Roblox password or customer API key. Authentication takes place through Roblox, and Roblox permissions remain the final authority.

ConfigLatch cannot grant access that Roblox has not granted.

Local-first architecture

ConfigLatch v0.23.1 is a local-first Windows desktop application.

Profiles, Saved Releases, safeguards, local approvals and activity records are stored on the user’s Windows device.

Hosted Team Workspace is not active in this release.

OAuth protection

Sensitive OAuth material is protected using Windows security facilities associated with the current Windows user.

Users remain responsible for:

  • Protecting their Windows account and device.

  • Using appropriate Windows sign-in security.

  • Preventing unauthorised physical or remote access.

  • Disconnecting ConfigLatch when access is no longer required.

  • Revoking access through Roblox when necessary.

Controlled write workflow

ConfigLatch separates preparation from publishing.

The release workflow is:

Prepare → Check → Approve → Publish → Verify

Changes remain staged until the user deliberately reviews and publishes them.

Before writing, ConfigLatch rechecks applicable conditions, including:

  • Authoritative Roblox state.

  • Draft identity and conflicts.

  • Compatibility approval.

  • Config safeguards and dependencies.

  • Local role restrictions.

  • Required approvals.

  • Emergency write-disable status.

Outcome-unknown protection

A network interruption or unclear platform response can make a publish result uncertain.

When ConfigLatch cannot confirm the outcome, it locks further writes. The user must refresh authoritative Roblox state and confirm the live result before another write can proceed.

This helps prevent unsafe duplicate or contradictory changes.

Compatibility protection

ConfigLatch uses compatibility controls designed to fail closed.

If the current app version is not approved or compatibility cannot be verified, publishing is blocked until an approved version is available.

ZULIC STUDIO may require a minimum approved version or activate an emergency write disable where reasonably necessary for safety, security or platform compatibility.

Config safeguards

Studios can define safeguards such as:

  • Required Config values.

  • Safe numeric ranges.

  • Allowed values.

  • Dependencies between Configs.

  • Protected Config keys.

  • Maximum changes per release.

  • Required gradual rollout.

  • Required Manager approval.

Rules are checked during preparation and again immediately before publishing.

Roles and approvals

The current release supports local Manager, Operator and Viewer responsibilities.

Studios may restrict publishing, protect Config keys and require an approval phrase before a release.

Approval phrases are not stored or logged in readable form.

These local controls supplement Roblox permissions; they do not replace or override them.

Activity integrity

ConfigLatch maintains a local activity trail for important release and policy actions.

Activity records use a tamper-evident chain designed to reveal unexpected alteration. Tamper evidence is not the same as absolute prevention, and users should still protect their Windows device and backups.

Data minimisation

ConfigLatch requests and processes only the Roblox permissions and information reasonably required for its core functions.

It does not request Roblox passwords or customer API keys.

It does not use Roblox information for advertising or unrelated user tracking.

Safe support and diagnostics

Users may review available diagnostic information before submitting feedback.

Never include:

  • Roblox passwords.

  • OAuth tokens.

  • API keys.

  • Confidential Config values.

  • Private production information.

  • Information you are not authorised to disclose.

Use the in-app Feedback feature or the ConfigLatch Support page for legitimate reports.

Security limitations

No software can guarantee that all mistakes, outages, platform changes, compromised devices or malicious actions will be prevented.

ConfigLatch reduces release risk but does not replace:

  • Roblox permissions and platform controls.

  • Secure Windows administration.

  • Studio testing and review.

  • Backups and recovery planning.

  • Professional judgement.

  • Appropriate staff and contractor access controls.

Reporting a security concern

If you believe you have found a ConfigLatch security issue:

  • Stop using affected write functionality.

  • Do not publicly disclose sensitive technical details.

  • Do not include passwords, tokens or confidential Config values.

  • Provide clear reproduction steps using non-production data where possible.

Report the concern to:

render@zulic.com.au

Use the subject:

ConfigLatch Security Report

ZULIC STUDIO will review legitimate reports and respond as reasonably practicable.

Roblox independence statement

ConfigLatch is an independent creator tool.

ConfigLatch and ZULIC STUDIO are not affiliated with, endorsed by or sponsored by Roblox Corporation.

Roblox is not responsible for ConfigLatch security, maintenance, support or operation.

Contact

ZULIC STUDIO
Email: render@zulic.com.au
ConfigLatch: https://www.zulic.com.au/configlatch

© 2018–2026 ZULIC STUDIO. All Rights Reserved.

bottom of page