SECURITY / ALPHA

THE MODEL CANNOT
ASK THE VAULT.

SHREDDAR reduces disclosure; it does not eliminate every privacy, correlation or re-identification risk.

LAST REVIEWED 02 SEP 2026
01

FAIL CLOSED

Classification, marker reconciliation, output inspection and upstream compatibility errors stop forwarding.

02

VAULT SEPARATION

AES-256-GCM mappings use authenticated session context and a 0600 key stored outside source.

03

BOUNDED STITCH

Only current-session placeholders and explicit reconstruction tokens can resolve. Unknown placeholders remain untouched.

04

NO RAW TELEMETRY

Receipts contain classes, counts, policy IDs, latency, routing and keyed fingerprints—never prompts or mappings.

05

SECRET BLOCKING

Credential-like values become typed presence markers and are tested not to persist in SQLite.

06

OUTPUT GUARD

Credential-like model output is blocked; newly introduced direct identifiers are removed before STITCH.

TRUST BOUNDARY

Raw context belongs inside your environment.

The self-hosted gateway processes source material locally. Only policy-approved protected representations may reach a configured upstream. The hosted site does not offer production raw-data processing.

KNOWN LIMITS

  • Detection coverage is not exhaustive.
  • Pseudonymized data may remain personal data.
  • SHARD is not cryptographic secrecy.
  • A receipt hash does not prove implementation security.
  • Independent privacy and security review is pending.
RESPONSIBLE DISCLOSURE

Report a suspected vulnerability privately through the project's verified Telegram destination. Do not include secrets, private documents, or live exploit data in a public channel.