Trust

Anyone can promise careful data handling. This page publishes proof: an automated job inside our infrastructure checks, every day, that the configuration our promises depend on is still in place — and publishes the result here whether it passes or fails.

Last verified August 1, 2026 at 8:19 PM UTC

All checks passing
  • Pass

    File versioning is off (deleted means deleted)

  • Pass

    The storage bucket blocks all public access

  • Pass

    Everything expires at 14 days even if our code fails

  • Pass

    No replication — exactly one copy exists until deletion

What this is

Our promises — deleted means deleted, no backups of your ciphertext, nothing publicly reachable — depend on specific storage and logging configuration: versioning off, replication off, no backup copies, public access blocked, log retention capped at 30 days. A scheduled job reads that live configuration every day and compares it to what our security page claims.

Configuration is proof in a way promises are not: it is what the system actually does, not what we say about it. If we ever broke a promise — deliberately or by mistake — this page would say so the next day. The same checks feed the evidence file for our independent audits.