THREAT MODEL.

subrosa · v0 · closed beta · 2026-08-30

How to read this document. Every claim here is scoped to what is running right now. Anything not yet true is marked PLANNED and stays marked until it ships. We would rather publish an unflattering fact than an aspirational one: a privacy service that overclaims once is done. When this document and our marketing disagree, this document wins.

01WHAT SUBROSA IS TODAY

Subrosa will be private GPU rendering for ComfyUI creators. During closed beta, what exists is the account layer: numbered accounts, credentials, a prepaid credit ledger, and invite codes. No rendering jobs flow yet. This document will grow a full execution section when they do — see §07 for the architecture we are building and its honest limits.

02WHAT WE STORE

The complete list. There are no other tables.

DataContentsWhy
Account recordRandom account number, created-at, active/frozen flagThe account is the number
CredentialsYour public keys only: Ed25519 master public key; passkey credential id + public key + signature counterVerifying that it's you
LedgerAppend-only credit entries: kind, amount, timestamp, reference, noteYour balance is its sum
Optional contactOne nullable field you can set and clear yourself; empty unless you add itBalance-low notices, if you want them
API tokensSHA-256 hashes of extension tokens you mint (never the tokens)Headless client auth
Invite codesSHA-256 hashes, batch label, used flagBeta gating without identity
Admin audit logEvery action our operators take: who, what, whenWe watch us, so you can

03WHAT WE DO NOT STORE

04KEYS AND SIGN-IN

05WHAT OUR INFRASTRUCTURE PROVIDER SEES

The control plane runs on Cloudflare (Workers, Durable Objects, D1, R2). We chose a large provider deliberately — availability and DDoS survival are also security properties — and we name the cost precisely:

06LEGAL PROCESS

Subrosa is operated from Canada; formal entity details will be published before public launch. Served with valid legal process, we can produce what §02 lists: a numbered account's balance history, credential public keys, token hashes, and the optional contact field if you set one. We cannot produce names, browsing history, IPs, or content, because they were never collected. We will contest overbroad demands, and we designed the system so the truthful answer to most demands is that the data does not exist.

07PLANNED — PRIVATE EXECUTION

Nothing in this section is running yet. It is the architecture under construction, published now so you can hold us to it — and so the limits are on record before the marketing exists.

08THE FLOOR

Subrosa is content-neutral about lawful work and architecturally unable to inspect it. Two categories are prohibited absolutely and enforced at the account and catalogue layer: CSAM and non-consensual intimate imagery of real people, including sexual deepfakes. A no-inspection service still has a spine: accounts violating the floor are terminated, prepaid balances and all, and we cooperate with lawful process as §06 describes.

09RETENTION

DataLifetime
Auth challenges10 minutes
Portal sessions4 hours
Ledger & account recordLife of the account (it is your balance)
Invite hashesDeleted at public launch, with this line updated
Request logs / analyticsNever existed
Job contentN/A today; designed never to be stored (§07)

10VERIFICATION

The ComfyUI extension and GPU worker are being built in the open on a shared open-source core. The control plane is small and private during beta; what of it becomes public is a pre-launch decision we will make in writing. Independent audit of the no-retention claims is a launch commitment, not a beta one — until then, this document is the contract and your skepticism is appropriate.

subrosa threat model v0 · 2026-08-30 · changes are dated and kept honest
⬡ sub rosa: under the rose