Trust and security
No commercial payload byte and no payload key ever touches our servers. Under listing, signatures of files you chose to list do cross; nothing derived from an unlisted file ever does, and nothing that can reconstruct a listed file’s content is stored in the clear.
The dashed line
Your files stay where they are. This tab (or the companion app) reads them to build a private index called your vault. Nothing derived from an unlisted file ever leaves. If you list a folder, coarse facts and fingerprints about its files go to Mass Employment so requests can find you. If you deliver work, it goes encrypted from your device to the buyer’s own storage. We never hold it and never hold the key.
Published keys
Devices verify what we sign, offline, against the keys published at /.well-known/massemployment-keys.json. A device that cannot verify uploads nothing.
Not built yet The signing key ceremony has not been run, so the document currently lists no keys.
What we never do
- No face recognition. Refused, not deferred.
- We never hold a commercial payload byte or a payload key.
- We never compute or show a count of hidden matches.
- We never store anything about health, faith, sexuality, immigration or children.
- We never pay differently for who a person is.
What is built today
We say what is built. Anything marked Not built yet is a plan, not a feature.
- The control plane, its origin and its backups: built.
- This site: built.
- The vault, the engine and the market: not built yet.
- Listing and the Work Registry: not built yet, gate G6.
We have not had a third-party security test yet. We will say so here when we have.
Report a problem
Write to security@massemployment.com. There is no bug bounty yet, and we say so rather than imply one.