Dual-End Public Cloud CDN & Zero-Knowledge Isolation

Dual-End Public Cloud CDN Moat:
Why It Is Physically Impossible for Us to Intercept or Store Your Data

DSHost utilizes a dual-ended public cloud CDN (EdgeOne / Cloudflare) architecture with in-memory blind stream piping. Both ends are encapsulated by public cloud edge infrastructure, while our relay operates purely as a stateless memory bridge with zero data persistence capability by physical design.

🛡️ Dual-End CDN TLS Encapsulation & Physical Isolation Topology

Browser Client PC / Tablet / Mobile 🔒 Endpoint 1 Public Cloud CDN EdgeOne / CF TLS 1.3 Envelope DDoS Guard & Edge dshost.me Relay In-Memory Stream ⚡ NO DISK / NO DB LOG Hashed Tokens Only ✕ Cannot Read / Store Transient Memory Pipe Public Cloud CDN EdgeOne / CF WSS Tunnel Secure Dual Bridge Host Your Machine 🔒 Endpoint 2

1. Dual-End Public Cloud CDN Encapsulation (Physical Isolation)

Both the browser requests and the developer machine's agent connection pass through Tier-1 public cloud edge networks (e.g. Tencent Cloud EdgeOne / Cloudflare) for TLS 1.3 cryptographic encapsulation. Our relay backend is fully wrapped by public cloud edge gateways, meaning traffic in transit is secured by enterprise-grade public cloud hardware boundaries.

2. In-Memory Chunk Piping —— Zero Disk Retention by Design

Even as the relay service operator, our architecture contains zero storage media for payload data. Data streams transiently through low-level Node.js memory buffers and are immediately garbage-collected upon transmission. The system maintains zero database tables or disk files for storing code, prompts, or session logs.

3. Zero-Knowledge Irreversible Hashing (SHA-256 / scrypt)

Device tokens are displayed only once at creation. The server database retains only one-way irreversible SHA-256 digests and prefixes, and user passwords use salted scrypt. Even with an adversarial database dump, original credentials can never be recovered.

Back to Home & Launch Workspace →