CURRENT ALPHA SECURITY MODEL

Security by explicit boundaries

Security by explicit boundaries

Security by explicit boundaries

Wehron separates ordinary browsing from deliberate, case-bound OSINT work through visible modes, isolated sessions, narrow privileged interfaces, and fail-closed handling. This describes a private engineering alpha—not certification or anonymity.

Wehron separates ordinary browsing from deliberate, case-bound OSINT work through visible modes, isolated sessions, narrow privileged interfaces, and fail-closed handling. This describes a private engineering alpha—not certification or anonymity.

Wehron separates ordinary browsing from deliberate, case-bound OSINT work through visible modes, isolated sessions, narrow privileged interfaces, and fail-closed handling. This describes a private engineering alpha—not certification or anonymity.

The mode boundary

Browser Mode owns one profile and initializes no OSINT services. OSINT Mode requires restart and owns one session and runtime per case. Cookies, storage, cache, authentication, downloads, preloads, and privileged objects never cross. One credential-free HTTP(S) address can transfer only deliberately after the destination analyst and case are active.

Remote pages remain untrusted

Remote pages use sandboxed Chromium with context isolation, Node disabled, no remote preload or bridge, HTTP(S)-only navigation, permissions denied by default, no certificate bypass, no silent HTTPS downgrade, and narrow typed sender-checked IPC.

Research and evidence

An fsync-backed append-only SHA-256 chain supports atomic screenshot, MHTML, manifest, checksums, and research anchor. Fresh verification occurs before PNG no-network preview. MHTML never replays. The chain is tamper-evident, not tamper-proof, signature, authorship, or chain-of-custody proof.

Downloads and interrupted work

Downloads require consent with cancel as the default, are case-scoped and hashed, and never auto-open. Recovery is exact-state only before runtime; ambiguous, corrupt, and legacy material stays preserved and blocking. macOS Trash is not secure erase.

Local-first does not mean anonymous

There is no Wehron cloud case service, but sites and search providers receive ordinary requests. Wehron is not VPN, Tor, anti-detect, crawler, CAPTCHA bypass, autonomous agent, malware scan, safe browsing, forensic certification, or defense against control of an unlocked Mac.

Current alpha limitations

Plaintext structured storage; feasibility-only SQLCipher and portable package; no production backup or recovery; analyst labels are not access control; same-case site state can survive analyst handoff; dynamic capture may use reduced-resolution or viewport fallback; no case deletion or ephemeral cases; no signing or notarization; no production update feed; internal preview only and no public download.

Security report

Report privately to security@wehron.de. Do not post sensitive reports publicly.