ZeusMix Security Model
Trust-Minimization, Zero-Fingerprinting & Air-Gapped Transaction Safeguards
ZeusMix is engineered around mathematical trust-minimization and threat mitigation against both network-level eavesdroppers and browser-level exploit vectors.
1. Non-Custodial Architecture
ZeusMix does not custody user funds. The platform generates single-use ephemeral gateway addresses tied strictly to user-defined routing rules. Funds are forwarded algorithmically upon block confirmation without human intervention or centralized escrow retention.
2. Zero JavaScript Security Guarantee
Modern web surveillance and malicious exploit vectors heavily exploit client-side JavaScript execution:
- WebGL Canvas Fingerprinting: Leaks unique GPU render traits to silently de-anonymize Tor users across sessions.
- Clipboard Hijackers: Malicious browser extensions replacing copied Bitcoin addresses during paste operations.
- DOM Injection: Supply chain attacks via compromised external NPM packages or CDN scripts.
/no-js/. It executes with exactly 0 bytes of client JavaScript, operating flawlessly with Tor Browser set to Safest Security Level.
3. Strict Privacy: Zero Tracking, Zero Cookies, Zero Server Logs
ZeusMix enforces an uncompromising zero-footprint privacy architecture:
- Zero Cookies: Zero
Set-CookieHTTP headers, zero client-sidedocument.cookie. No tracking cookies, session identifiers, or persistent user profiling tokens. - Zero Server Access Logs: The Caddy edge reverse proxy is explicitly configured with
log { output discard }. Client IP addresses, request paths, visit timestamps, and User-Agents are dropped in real-time and never written to disk or storage. - Zero Third-Party Telemetry: No Google Analytics, Meta Pixel, or external tracker scripts. All typography and assets are 100% self-hosted locally under
/fonts/. Live Bitcoin mempool fees are proxied locally via/api/v1/mempool/to prevent IP leaks to block explorers. - Volatile In-Memory Routing: Ephemeral gateway mappings and payout recipient addresses exist strictly in volatile RAM. They are purged automatically upon transaction broadcast or session expiration (60m).