OncePad changelog
Material product, security, privacy, and documentation changes
— trust and discoverability
- Removed Pirsch and all other remotely hosted JavaScript from every page; the CSP now allows scripts only from OncePad itself.
- Published the disclosure policy, operator page, encryption-format specification, conformance vectors, audit status, and incident-history statement.
- Added canonical host and trailing-slash redirects, sitemap
lastmoddates, explicit OAI-SearchBot rules, IndexNow support, breadcrumbs, and new task-focused guides. - Published a service-comparison hub and sourced comparisons with Bitwarden Send, Yopass, and PrivateBin.
- Standardized the displayed product name as OncePad.
— encrypted file sharing
Added browser-encrypted file handoff up to 25 MB. Filenames and MIME types are sealed inside the encrypted manifest; the storage provider receives ciphertext and transfer metadata, and one successful redemption retires the file capability.
— public launch
Launched the passphrase-only, key-less-link design with AES-256-GCM, a generated 7-word passphrase, one atomic reveal, 24-hour expiry, RAM-only text storage, strict CSP, and SRI-pinned browser code.