Verification guide
Verify It Yourself
This walkthrough is for technical users who want to inspect what PrivShare sends over the network during normal share creation and retrieval.
Use Test Data Only
Do not use real secrets for this walkthrough. Use a harmless sentinel value that you can safely search for in DevTools.
Creation request:
POST /api/shares
Retrieval request:
POST /api/shares/[id]/retrieve
Fragment-key link:
/s/[id]#key=...
Password-share link:
/s/[id]Network Check
The goal is to confirm that plaintext stays out of request URLs, request bodies, and responses.
- 1Open browser DevTools and switch to the Network tab.
- 2Create a test text share with a harmless sentinel value that is not a real secret.
- 3Inspect the creation request.
- 4Confirm the request contains ciphertext, IV, lifecycle fields, and verifier or password-protection metadata only.
- 5Confirm your sentinel plaintext is absent from the request URL, request body, and response.
- 6Open the generated recipient link in a fresh tab.
- 7Confirm the fragment key is present only in the visible URL for fragment-key shares and is not sent in HTTP requests.
- 8Trigger decryption in the browser.
- 9Inspect the retrieval request.
- 10Confirm retrieval sends only a verifier and receives ciphertext/IV or encrypted-file download metadata.
Additional Checks
Repeat the same inspection for other share modes when you can do so safely.
- Password shares: confirm the raw share password is absent from requests.
- Environment-variable shares: confirm variable names, values, comments, and variant names are absent from requests.
- File shares: confirm file upload requests carry encrypted bytes only. Provider-console metadata verification is owner-side QA.
- Recipient emails: confirm delivered emails contain keyless /s/[id] links only.
What This Does Not Prove
DevTools inspection is useful, but it is not a complete audit.
- It does not prove future deployments will serve identical JavaScript.
- It does not prove production Vercel, email, S3, CloudFront, or database settings are correct.
- It does not prove strict script CSP, custom rate limiting, or production observability are implemented.
- It does not protect against compromised devices, malicious extensions, or recipients copying plaintext after decryption.
Keep reading
Explore the rest of the security documentation
Every security page links to the others so you can move through the full model without using the browser back button.