
Scorchpad
Zero-knowledge encrypted pastebin. The key never leaves your
ScorchPad works differently. Your browser generates a 256-bit key, encrypts your text with AES-256-GCM locally, and sends only the encrypted blob to the server. The key lives in the URL fragment -browsers never include that in HTTP requests. So my server never sees it. Ever.
What that means practically:
I cannot read your pastes
I cannot comply with data requests - there's nothing to hand over
I cannot identify you by IP - raw IPs are never stored
A few implementation details I'm proud of:
Burn-after-reading is atomic via a Lua script on Redis - race-condition proof
PBKDF2-SHA256 at 310,000 iterations for password-protected pastes
Monthly warrant canary published
Fully open source
I also document my own weaknesses openly - including the JS supply chain risk. Because honest threat modeling matters more than marketing.
Would love feedback from the community - especially on the threat model.
About
Most privacy tools are just promises. I wanted structural impossibility, a pastebin where even I can't read your data. Your browser encrypts it. The key never touches my server. Not a policy. Just math.

Comment