Security model

Encrypt, claim once, validate.

The sender generates an AES-256-GCM key, IV, lookup and claim token with Web Crypto. The backend stores ciphertext and hashed claim material. The fragment is removed before prompts or claim traffic.

Controls

Responsible disclosure

Email security@dermoptera.work. GitHub private vulnerability reporting will also be available after repository publication. Do not open a public issue or send live credentials or user state.