Encryption & Browser Sandbox

We utilize browser cryptographic APIs and strict Transport Layer Security (TLS) to ensure end-to-end client-side privacy.

Encryption in Transit

All web pages, scripts, WASM binaries, and model assets are served over secure HTTPS protocols:

  • Enforced HTTPS: All HTTP traffic is automatically upgraded to TLS 1.3 encrypted HTTPS.
  • HSTS & Security Headers: Strict Transport Security (HSTS), COOP, and COEP headers enforce cross-origin isolation.

Client Cryptographic APIs

Our cryptographic utility tools run directly on Web Crypto API (`window.crypto.subtle`):

  • Local Hashing & Ciphering: SHA-256, AES-GCM, and HMAC computations are executed locally inside your browser process.
  • No Server Keys: Your encryption keys and plaintexts never leave your local client device.