zeroNet Redact: source evidence and limitations

Developer-maintained evidence, reviewed on 2026-10-03. These findings describe the GitHub source snapshot below, not a verified App Store binary or an independent security audit.

Commit: adb7f1d3cf3f3b3848cb6f9b53bfcc06d2d25027

PDF export removes covered text

The export path calls MuPDF redaction with PDF_REDACT_TEXT_REMOVE and image-pixel redaction. It is more than a visual rectangle over selectable text. Vector line art is explicitly left intact, and embedded-file removal is a placeholder: this is not evidence that every hidden object, attachment or metadata field is sanitized.

Text recognition runs through Apple Vision

The reviewed OCR path creates VNRecognizeTextRequest and processes a local image using VNImageRequestHandler. Recognition results still need review; this does not establish perfect detection.

Video face detection and manual covers are different paths

The source includes local face detection on sampled video frames, cross-frame track smoothing and per-frame rendering. Manual covers have a fixed rectangle and an active time interval. Sampling and movement can leave gaps: preview the complete export and do not assume perfect tracking.

Local editor drafts are encrypted

The draft store serializes drafts, encrypts them using CryptoEngine, and writes the encrypted data locally. CryptoEngine uses a 256-bit key and AES.GCM.

Verification scope

Implementation and test definitions were inspected. Xcode/iOS tests were not executed; test files are not passing test results. Local processing in the inspected paths alone does not prove the entire app has no network activity in every situation.