Sealed messages with provable expiry and a tamper-evident record — on a server that holds no private key and therefore cannot read what it stores.
Zeroize is the standard term in defence cryptography for destroying key material.
Expiry here does not delete your data. It destroys the key that reads it, and deliberately keeps the ciphertext — so the guarantee can be demonstrated rather than asserted. The bytes are still on the server, and nobody can read them.
Deleting data is a policy promise: it fails the moment one server quietly keeps a copy, and in this threat model that server is the adversary. Destroying the key is a mathematical promise — it holds even against the machine that cheated.
Every guarantee is paired with its limit. The common failure in secure communications is not weak cryptography but a claim that outruns it.
Nothing here asks to be taken on trust.
The implementation ships with suites an evaluator runs themselves: the cryptographic guarantees, interoperability between two independent implementations, hardware custody against real silicon, and an adversary holding root on the node — which reports its own outstanding finding rather than only its successes.