セキュリティと安全

セキュリティは目的そのものであり、単なる機能ではありません。

CIND3R3LLA is a consent firewall: nothing is published unless its author asked for it. This page explains how that is enforced, and what the planned CSAM screening stage will and will not do.

CSAM & content screening (in development) 開発中

This is where CIND3R3LLA is going, and it is not there yet. The design: every image and video is hashed at receipt, independently of consent, and compared against databases of known abuse material. A match is quarantined, encrypted, withheld from every public path and preserved for the authorities, never quietly deleted, because deleting a match destroys the evidence that makes a prosecution possible. Today the storage and quarantine machinery is built and no detection provider is connected, so no screening runs. Note the limit that will remain even once it does: hash matching detects known material only. It cannot detect new material, and a no-match result is not a statement that anything is safe.

同意
CSAM screen (planned)
公開
パスワードレス

パスキー(WebAuthn / FIDO2)。デバイスに紐づき、フィッシングにも総当たり攻撃にも耐性があります。共有パスワードは存在せず、漏えいや使い回しの対象になるものがありません。

あなたのデータはあなたのもの

最小権限で分離されています。計画中のローカルAIが実現すれば、審査も会話もお客様のインフラの外に出ることはなく、信頼しなければならない第三者の処理者も存在しません。

通報と削除

審査の後の第二の防衛線。公開されたコンテンツは誰でも通報できます。運営者がレビューして削除し、すべての操作が監査ログに記録されます。

脆弱性を発見しましたか?

リポジトリに記載のセキュリティ窓口まで非公開でご報告ください。責任ある開示にはクレジットを掲載し、すべての報告を真剣に受け止めます。

セキュリティポリシー