Security model
Encrypt, claim once, validate.
The sender generates an AES-256-GCM key, IV, lookup and claim token with Web Crypto. The backend stores ciphertext and hashed claim material. The fragment is removed before prompts or claim traffic.
Controls
- Atomic one-time claim and same-transaction usage.
- Claim-time expiry independent of cleanup.
- Exact Allowed Origin, rotatable Project key and disablement.
- Strict app ID, schema version and runtime validation.
- Existing-state Replace or Cancel before claim.
Responsible disclosure
Email security@dermoptera.work. GitHub private vulnerability reporting will also be available after repository publication. Do not open a public issue or send live credentials or user state.