Security & Threat Model
Hush is built with a specific threat model in mind to ensure your secrets remain secure while maintaining usability.
- Data breaches: We cannot leak your plaintext because we never have it.
- Chat history persistence: Secrets shared in chat logs become useless after one view.
- Accidental exposure: Passphrase mode prevents someone who finds the link from opening it without the second factor.
- Compromised devices: Malware on the sender or receiver device can capture data before encryption or after decryption.
- Screenshotting: The intended recipient can always take a screenshot or copy the text.
- Metadata logging: We temporarily retain HMAC-hashed IP identifiers and time-window metadata for rate limiting and abuse prevention. Raw IP addresses are not stored in the application database. Infrastructure providers may process connection metadata under their own policies.
When you create a secret with a passphrase, Hush changes how deletion works to allow for typos. In normal mode, the server destroys the secret the millisecond the recipient clicks "Reveal Secret". In passphrase mode, destruction is delayed until your browser successfully decrypts the secret and sends a finalize token.
This means if an attacker modifies your browser's code to prevent the finalization request, the secret might not be destroyed immediately (though it will still expire eventually). We consider this a best-effort deletion guarantee in exchange for a significantly better user experience where wrong passphrases can be retried.
Responsible Disclosure
If you find a security vulnerability, we will respond promptly.
To read more deeply into security practices, visit the Hush Security Blog.