Why Plausible Privacy Software.
Plausible deniability isn't a feature you bolt on. It's a posture the architecture either holds or it doesn't. Plausible Privacy Software is the suite we build to hold that posture by construction — for you, for your team, and for the people who depend on you to not be the source of their exposure.
The shape of the problem.
Most "privacy" software protects the channel. PPS protects the substrate. The distinction is the difference between a courier in a locked car and a courier who never carried the package in the first place.
Channel protection — TLS, end-to-end encryption, encrypted storage — is necessary. It is not sufficient. Once the substrate exists, the substrate becomes the target: subpoena, settlement-induced disclosure, downstream breach, AI-trained-on-your-data, model-inversion. The substrate is what gets pulled.
Substrate protection means designing the system so the load-bearing data either does not exist, does not persist, does not centralise, or carries no probative weight when it does. That is what PPS is for.
What's in the suite.
PPS is a small set of tools that compose: an Engine that does the substrate decisions; an Inject layer that places plausible cover traffic where bare absence would itself be probative; a Purge layer that removes residual artefacts in a way the file system cannot reconstruct; a Tidy layer that keeps the working set clean; a Shard layer that separates what must be kept from what must not co-locate; a Swarm layer that distributes what should not centralise; and a USB layer for the airgap path when the network itself is the threat.
You will not need every layer. You will need the layers your threat model says you need. The point of building it as a suite — not a monolith — is that the layers compose without coupling. Every one is independently auditable, independently shippable, and independently replaceable.
The PPS layers.
Each layer is independently auditable, shippable, and replaceable. Compose only the ones your threat model needs.
Engine
Substrate decisions — what gets stored, what doesn't, where the load-bearing data lives.
Inject
Plausible cover traffic where bare absence would itself be probative.
Purge
Removes residual artefacts in a way the file system cannot reconstruct.
Tidy
Keeps the working set clean — the data on disk matches the data you mean to have.
Shard
Separates what must be kept from what must not co-locate.
Swarm
Distributes what should not centralise. The substrate has no single point of subpoena.
The substrate is what gets pulled.
— PPS engineering note, internal
Want to talk about your substrate?
First conversation is free, the NDA is mutual, and if PPS isn't the right shape we'll say so before either of us has invested an hour.