Why I Started Looking for Evidence

For years, I described SecurityNet in very simple terms.

  • No cloud storage.
  • No central tracking.
  • No server logs.

Those statements reflected the way I'd designed the software.

Files travel directly between computers.

Messages aren't stored on external servers.

Communication takes place between the people involved, not through a central archive.


From an engineering perspective, those principles shaped almost every decision I made.

But at some point, I began asking myself an uncomfortable question.

How much of what I believed was actually being verified?

As software developers, it's easy to become overconfident.

We know our own code.

We know what we intended to build.

We know how a feature is supposed to behave.

And after years of working on the same project, intention can easily become a substitute for evidence.


I started to realise that there was a difference between saying that SecurityNet doesn't store communication activity and actually demonstrating that behaviour.

Those aren't the same thing.

A privacy claim isn't automatically true simply because the software was designed with good intentions.

The only way to know is to investigate.

That realisation changed my thinking.


Instead of asking whether I trusted my own software, I started asking different questions.

  • What information was actually being retained?
  • What evidence could I collect?
  • If somebody challenged one of my privacy claims, what could I show them?

Those questions led me somewhere I didn't expect.

Away from the application itself.

Away from the website.

And directly onto the server that helps SecurityNet establish connections.