Remote images (https://…) load by default so documents render completely — but a tracking pixel would otherwise leak your IP with zero indication. The policy:
A visible indicator appears whenever the document contains remote content; press i to drop all remote images to placeholders (again to re-allow).
HTTPS-only: plain-http:// URLs are never fetched. URLs with embedded credentials are never fetched either.
No credentials, cookies, or Referer are stored or sent. Redirects capped at 3, 8s timeout, 8 MiB body limit — a tarpit degrades to a placeholder, never a hang.
Blocked URLs never reach the loader, so a malicious doc with 10k remote images costs layout only.
Enforced in src/core/remote_policy.zig and pinned by unit tests.