ZeroNet Space: source evidence and limitations

Developer-maintained evidence, reviewed on 2026-10-03. These findings describe the GitHub source snapshot below, not a verified App Store binary or an independent security audit.

Commit: 12952609c750c2a3f0753fab1388ad6a6353cc86

Password-based AES-256-GCM encryption

The encryption service derives a 32-byte key with PBKDF2-HMAC-SHA256 and uses AES.GCM to seal data. File imports pass through the encrypted-file storage service.

Audio imports use encrypted storage

The audio import service validates the input and saves it through encrypted storage. A test definition checks that stored bytes differ from the original and decrypt back to the original audio bytes; this test was not run during this review.

Free import allowance

The source defines the free import limit as 75 items. Check the current App Store listing for released features and purchase options.

Verification scope

Implementation and test definitions were inspected. Xcode/iOS tests were not executed; test files are not passing test results. Local processing in the inspected paths alone does not prove the entire app has no network activity in every situation.