FAIL CLOSED
Classification, marker reconciliation, output inspection and upstream compatibility errors stop forwarding.
SECURITY / ALPHA
SHREDDAR reduces disclosure; it does not eliminate every privacy, correlation or re-identification risk.
LAST REVIEWED 02 SEP 2026Classification, marker reconciliation, output inspection and upstream compatibility errors stop forwarding.
AES-256-GCM mappings use authenticated session context and a 0600 key stored outside source.
Only current-session placeholders and explicit reconstruction tokens can resolve. Unknown placeholders remain untouched.
Receipts contain classes, counts, policy IDs, latency, routing and keyed fingerprints—never prompts or mappings.
Credential-like values become typed presence markers and are tested not to persist in SQLite.
Credential-like model output is blocked; newly introduced direct identifiers are removed before STITCH.
TRUST BOUNDARY
The self-hosted gateway processes source material locally. Only policy-approved protected representations may reach a configured upstream. The hosted site does not offer production raw-data processing.
KNOWN LIMITS
Report a suspected vulnerability privately through the project's verified Telegram destination. Do not include secrets, private documents, or live exploit data in a public channel.