Zero-knowledge by construction
Most services promise not to look at your data. We built it so we cannot. Profiles, folders and warmed sessions are encrypted on your device with a key derived from a passphrase that never leaves it. What arrives at our servers is ciphertext with an identifier and a timestamp.
That means cookies, local storage, fingerprint configuration, notes and any proxy credentials inside a profile are opaque to us, to anyone who compromises our infrastructure, and to anyone who compels us to hand over what we hold.
Team sharing without handing us the keys
Sharing normally means giving the server a key. Instead, each user has an X25519 keypair whose private half is wrapped with their own passphrase-derived key. A workspace has its own data key, and that key is sealed individually to every member’s public key. The server stores and relays sealed envelopes it cannot open.
- Context-bound envelopes. Each sealed envelope is bound to the workspace it belongs to, so an envelope cannot be lifted from one context and replayed in another.
- Trust on first use, then pinned. A colleague’s public key is pinned the first time it is seen. If the key later changes, sharing stops and you are shown the new fingerprint to verify out of band — a substituted key is never silently trusted.
- Real cryptographic revocation. Removing a member does not merely delete a row: the workspace key is rotated and re-sealed to the remaining members only. The removed member cannot decrypt anything published afterwards, even with a copy of the database.
A log that cannot be quietly rewritten
Every membership and access-control change is appended to a per-workspace audit log where each entry carries the hash of the one before it. Three properties matter:
- Hash-chained — editing an old entry breaks every hash after it.
- Actor-signed — membership events carry an Ed25519 signature from the user who performed them. An operator who rewrites history and recomputes the chain still cannot forge that signature, so the forgery is detected.
- Server-anchored and exportable — the log can be exported and verified offline against the server’s signed anchor, so verification does not depend on trusting the server at the moment you check.
Access control
Workspaces have four roles — owner, admin, member, viewer — with per-profile access lists on top. Access lists are default-deny where the workspace is configured that way: a profile nobody has been granted is served to nobody, rather than to everyone by accident. Removing someone from a workspace also strips them from every profile list, so re-adding them later does not silently restore old access.
What stays on your machine
Profile isolation, browser launching, fingerprint injection and the local automation API all run locally. Websites you visit inside a profile are contacted by your machine or your proxy — that traffic never passes through us, and we do not log it because we never see it.
The honest trade-offs
A design like this has costs, and you should know them before you buy rather than discover them later.
- Lose your passphrase and the data is gone. There is no reset and no recovery. We hold no key, so there is nothing for support to escalate. Keep it somewhere safe.
- We cannot moderate what we cannot read. Enforcement of our Acceptable Use Policy rests on account-level signals, your conduct toward our infrastructure, and credible reports — not on inspecting your content.
- No product defeats every detection method. Fingerprint consistency is one signal among many; network reputation, behaviour and account history are others we do not control. We publish our known limitations rather than claim invisibility, and we make no promise about how any third party will treat your traffic.
Operational practices
- TLS for all traffic; modern memory-hard password hashing; scoped, expiring access tokens.
- Rate limiting on authentication, and boundary validation on inputs.
- Least-privilege access to production, with changes recorded.
- Encrypted backups of a datastore that holds only ciphertext.
- Security reports are welcomed through the contact form and investigated; please give us a reasonable window to fix an issue before disclosing it.