(no title)
burnbox | 1 month ago
1. Argon2id, 64MB memory, 3 iterations. Memory-hard beats iteration count.
2. Encrypted blob + padded filename (256 bytes fixed) + expiry timestamp. No IP logging—downloads proxy through Netlify so Supabase never sees user IPs.
3. Threat model documented at /security. Trust assumption is TLS + uncompromised JS delivery. Source hashes published for verification without self-hosting.
We've had interest from lawyers and incident response teams. Use cases at /use-cases.
No comments yet.