Security

An honest account of what Palarid's architecture protects against — and what it does not.

Last reviewed: July 2026

The strongest security property

There is no server holding your data. Palarid has no user database, no account system and no stored personal records. A breach of our hosting would expose no user information, because none is there. This is the single most meaningful security property of the product, and it comes from the architecture rather than from a policy promise.

What browser storage does not protect against

Local storage is not encrypted storage, and we will not call it that. Anyone with access to your unlocked device and browser profile can read what Palarid has saved. Browser extensions with broad permissions can read it too. If you share a computer, use a separate browser profile, or do not store sensitive material in Palarid.

Your device's own protections — screen lock, disk encryption, account separation — are what actually guard this data. Palarid sits inside them; it does not replace them.

What we have hardened

Fixed in July 2026

Recording these rather than quietly patching them, because a security page that only lists strengths is not a security page.

Known gaps

Still open, stated plainly.

Reporting a vulnerability

If you find a security issue, please report it before disclosing it publicly. We will confirm receipt, investigate, and credit you if you would like to be credited.

If you are worried about your own data

← Back to Trust Centre