Trust Center

Shhhs Trust Center

Trust in Shhhs is based on verifiable boundaries: client-side encryption for supported secret content, metadata-only operations, no secret recovery, and no AI processing on secrets. Signed legal, audit, SLA, and DPA materials are available only through reviewed commercial or Enterprise processes.

01

Security

Supported secret content is encrypted by the client before upload. Shhhs stores and transfers ciphertext plus the operational metadata required to enforce access and lifecycle rules.

  • Client-side encryption for supported secret content
  • No secret recovery
  • Preview-safe private links

02

Privacy and data handling

Shhhs does not read, profile, train on, index, or sell secret content. Operational metadata exists only where needed for lifecycle, abuse control, billing, audit, and support boundaries.

  • No AI processing on secrets
  • Metadata-only operations
  • No plaintext support access

03

Service status

Shhhs publishes current public service posture at status.shhhs.net. That page does not claim historical uptime, an external SLA, or incident automation beyond the deployed service controls.

  • Public status page
  • No invented uptime history
  • Incident handling cannot recover secrets

04

Subprocessors

Current public subprocessors are described by function and boundary. Shhhs does not use subprocessors to process plaintext secret content with AI or analytics.

  • Cloudflare infrastructure
  • Paddle billing
  • Resend email when configured

05

Legal documents

Public legal and billing pages expose only the currently configured policy boundary. Commercial contracts, DPA review, and Enterprise materials are handled through the contact flow.

  • Canonical policy pages
  • Contact for official requests
  • No invented company data

06

Security reports

Responsible disclosure is accepted through the contact flow until a dedicated security contact or reporting URL is configured. Reports must use test data and must not include live secrets.

  • Use test data only
  • No live tokens or full links
  • Coordinated remediation

07

Security review packet

Technical reviewers can start from a single public packet that links crypto boundaries, metadata retention, threat model, API, CLI, MCP, responsible disclosure, and current audit limitations.

  • docs.shhhs.net/security-review
  • Evidence over absolute claims
  • No external audit claim yet

FAQ

Does Shhhs process secrets with AI?

No. There is no AI processing on secret content.

Can Shhhs recover a secret?

No. Secret recovery would weaken the privacy model.

What can support recover?

Support can help cancel billing after billing validation, but cannot restore account access or secret content.