Security & safety

Security is the point, not a feature.

CIND3R3LLA is a consent firewall: nothing is published unless its author asked for it. This page explains how that is enforced, and what the planned CSAM screening stage will and will not do.

CSAM & content screening (in development) In development

This is where CIND3R3LLA is going, and it is not there yet. The design: every image and video is hashed at receipt, independently of consent, and compared against databases of known abuse material. A match is quarantined, encrypted, withheld from every public path and preserved for the authorities, never quietly deleted, because deleting a match destroys the evidence that makes a prosecution possible. Today the storage and quarantine machinery is built and no detection provider is connected, so no screening runs. Note the limit that will remain even once it does: hash matching detects known material only. It cannot detect new material, and a no-match result is not a statement that anything is safe.

Consent
CSAM screen (planned)
Publish
Passwordless

Passkeys (WebAuthn / FIDO2): device-bound, phishing- and brute-force-resistant. No shared passwords, nothing to leak or reuse.

Your data stays yours

Least-privilege and isolated. With the planned local AI, screening and conversations never leave your infrastructure, and there is no third-party processor to trust.

Reporting & takedown

A second line after screening: anyone can report published content. The operator reviews and removes it, and every action is audit-logged.

Found a vulnerability?

Report it privately via the security contact in the repository. We credit responsible disclosure and take every report seriously.

Security policy