This is really nicely done. One question. Since you state 'this is not zero-knowledge' because plaintext briefly hits your API over HTTPS, what precise architectural isolation protects that plaintext in memory while it is being encrypted?
That's an excellent question! It's currently running on Google Cloud Run, which to my knowledge, doesn't offer any encrypted memory options. So, as of now, there isn't any architecture in place to protect the plaintext.
It's definitely something we've thought about. And something we may pursue.
This is really nicely done. One question. Since you state 'this is not zero-knowledge' because plaintext briefly hits your API over HTTPS, what precise architectural isolation protects that plaintext in memory while it is being encrypted?
That's an excellent question! It's currently running on Google Cloud Run, which to my knowledge, doesn't offer any encrypted memory options. So, as of now, there isn't any architecture in place to protect the plaintext.
It's definitely something we've thought about. And something we may pursue.