Sicurezza e protezione

La sicurezza è lo scopo, non una funzionalità.

CIND3R3LLA is a consent firewall: nothing is published unless its author asked for it. This page explains how that is enforced, and what the planned CSAM screening stage will and will not do.

CSAM & content screening (in development) In sviluppo

This is where CIND3R3LLA is going, and it is not there yet. The design: every image and video is hashed at receipt, independently of consent, and compared against databases of known abuse material. A match is quarantined, encrypted, withheld from every public path and preserved for the authorities, never quietly deleted, because deleting a match destroys the evidence that makes a prosecution possible. Today the storage and quarantine machinery is built and no detection provider is connected, so no screening runs. Note the limit that will remain even once it does: hash matching detects known material only. It cannot detect new material, and a no-match result is not a statement that anything is safe.

Consenso
CSAM screen (planned)
Pubblicazione
Senza password

Passkeys (WebAuthn / FIDO2): legate al dispositivo, resistenti al phishing e agli attacchi brute-force. Nessuna password condivisa, niente da far trapelare o riutilizzare.

I vostri dati restano vostri

Privilegi minimi e isolamento. Con l'AI locale in programma, screening e conversazioni non lasciano mai la vostra infrastruttura, e non c'è nessun responsabile del trattamento di terze parti di cui fidarsi.

Segnalazione e rimozione

Una seconda linea dopo lo screening: chiunque può segnalare i contenuti pubblicati. L'operatore li esamina e li rimuove, e ogni azione viene registrata nel log di audit.

Avete trovato una vulnerabilità?

Segnalatela in via riservata tramite il contatto di sicurezza nel repository. Diamo credito alla divulgazione responsabile e prendiamo sul serio ogni segnalazione.

Policy di sicurezza