resources / security

Security, stated plainly

The short version: ZeroShade has not been independently audited, is not ready for live funds, and does not promise anonymity. Here is the rest.

Current status

No independent audit report has been provided or verified. We name no auditor because none has been verified. Do not use ZeroShade with real funds.
  • The hosted app is simulated and is not a live-money client.
  • No privacy guarantee is made. Privacy depends on many things outside this project.
  • We will not list an audit here until the report can be read and checked.

What the hosted API stores

DataNotes
Handle-owner associationsThe server retains the handle-owner association. The handle lookup endpoint only reports whether a handle exists, not who owns it. Claiming a handle without signing in dispenses fresh public recipient addresses, and recipients and anyone holding a public link can obtain the destination data relevant to them.
One-time recipient addresses and usageStored so the API can tell whether an address has been used.
Payment linksAmount, destination, status and reference.
Shared signed reportsThe signed payload is stored as shared, so whoever has the link can read it.
WaitlistA hash of the email, not the plain address.

What it does not store

Wallet private keys and seed phrases are not in the hosted database. The hosted process is API-only.

Not storing keys is a design choice, not proof of safety. It does not make the other stored data private.

Signatures and hashes

Signatures

  • Prove integrity, and that the signer controls the signing key.
  • Do not verify a real-world identity.
  • Detect changes after signing.
  • Are not encryption. A signed report can still be read in full.

Hashes

  • Turn an email into a fixed string.
  • Are not anonymization. A known or guessable email can be hashed and compared.
  • Should be treated as personal data.

The demo

The demo runs in memory in your browser. It sends no real funds, does not hide your real IP address, and loses all state when you refresh.

Report a problem

Read the Bug bounty page for safe scope and for how to ask for a private channel. Never post sensitive details publicly.

See it for yourself

Open the simulated demo