Shredit / Security
Security
Shredit publishes its source under AGPL-3.0 and keeps the service narrow by design.
Threat boundaries
The service is not a guarantee against screenshots, copied text, compromised devices, recipient actions, modified client code, or traffic correlation.
Report a vulnerability
Please use the security contact listed in SECURITY.md and /.well-known/security.txt. Do not include note contents, passwords, or full share links in a report.
Source
Open source - available for audit. This phrase means the source is available for inspection; it is not a claim that an independent audit has been completed.