SLIDINGBOX LLC

Security by data minimization

Slidingbox reduces exposure by keeping encryption keys with the client and limiting what the service stores, logs, and retains.

Client-controlled encryption

Encryption takes place before an item reaches Slidingbox. The service receives ciphertext and an initialization vector, but it does not receive the plaintext or encryption key and cannot decrypt the submitted item.

Short-lived storage

Each item has a time-to-live between 60 and 900 seconds. Retrieval is designed to remove an item after the first successful delivery, with expiry checked when an item is accessed as well as during scheduled cleanup.

Restricted operational data

Application logs are restricted to operational fields such as request identifier, route, status, duration, error code, and a short pointer prefix. Ciphertext, initialization vectors, keys, and payment signatures are excluded from the application's logging allowlist.

Abuse controls

The service applies request-size validation, per-IP limits, payer limits, malformed-credential penalties, strict pointer validation, and no-store response headers.

Payments

Before a paid retrieval is settled, the originating payer wallet address is checked against the digital-currency addresses on the OFAC Specially Designated Nationals and Blocked Persons List, and a matching request is refused without being charged and without the item being delivered. The check runs against a periodically refreshed copy of that list; it does not trace fund provenance, apply blockchain-analytics tooling, or screen any other list.

Paid retrievals settle through a third-party payment facilitator. Slidingbox does not hold customer funds, private wallet keys, or card and bank credentials. Settlement is recorded on the public Base blockchain, so payment activity is independently verifiable by anyone without our involvement. We reserve the right to refuse or block a payment and to terminate access, as described in section 3 of the Terms of Service.

Responsible reporting

To report a suspected vulnerability or security issue, email support@slidingbox.ai. To report abuse of the Service, email abuse@slidingbox.ai. Do not include live encryption keys, payment credentials, or sensitive customer data.

No certification or third-party security audit is claimed on this page.