Security Architecture
Your data security is the foundational pillar of EDNDrop. Because we utilize WebRTC, all file transfers are End-to-End Encrypted (E2EE) by default.
End-to-End Encrypted
WebRTC mandates encryption. All data sent between standard browsers via WebRTC is automatically encrypted using Datagram Transport Layer Security (DTLS). We do not have the keys, and we cannot intercept or decrypt your files. The traffic happens locally on your immediate network whenever possible.
Signaling Sub-Layer
The only data that routes through the EDNDrop NodeJS backend is the initial handshake. This payload only contains public networking metadata (e.g., ICE candidates, SDP tokens, and file names/sizes). Even this signaling layer occurs strictly over encrypted WSS (WebSocket Secure).
Ephemeral Memory
PINs and Share URLs exist completely in-memory on our server and are rigorously wiped when the browser tab is closed or a strict 30-minute Time-To-Live (TTL) is breached.