Trust
Anyone can promise careful data handling. This page publishes proof: an automated job inside our infrastructure checks, every day, that the configuration our promises depend on is still in place — and publishes the result here whether it passes or fails.
Last verified August 1, 2026 at 8:19 PM UTC
All checks passing- Pass
File versioning is off (deleted means deleted)
- Pass
The storage bucket blocks all public access
- Pass
Everything expires at 14 days even if our code fails
- Pass
No replication — exactly one copy exists until deletion
What this is
Our promises — deleted means deleted, no backups of your ciphertext, nothing publicly reachable — depend on specific storage and logging configuration: versioning off, replication off, no backup copies, public access blocked, log retention capped at 30 days. A scheduled job reads that live configuration every day and compares it to what our security page claims.
Configuration is proof in a way promises are not: it is what the system actually does, not what we say about it. If we ever broke a promise — deliberately or by mistake — this page would say so the next day. The same checks feed the evidence file for our independent audits.