Encryption & Browser Sandbox
We utilize browser cryptographic APIs and strict Transport Layer Security (TLS) to ensure end-to-end client-side privacy.
Encryption in Transit
All web pages, scripts, WASM binaries, and model assets are served over secure HTTPS protocols:
- Enforced HTTPS: All HTTP traffic is automatically upgraded to TLS 1.3 encrypted HTTPS.
- HSTS & Security Headers: Strict Transport Security (HSTS), COOP, and COEP headers enforce cross-origin isolation.
Client Cryptographic APIs
Our cryptographic utility tools run directly on Web Crypto API (`window.crypto.subtle`):
- Local Hashing & Ciphering: SHA-256, AES-GCM, and HMAC computations are executed locally inside your browser process.
- No Server Keys: Your encryption keys and plaintexts never leave your local client device.