Skip to content

Zero-PII Identity & Concurrency Model

Pluvira is architected around strict privacy-by-design and zero-knowledge principles. The system enforces concurrency quotas and licensing entitlements without tracking personal identities, media consumption, or cleartext network addresses.


1. Zero-PII User Identification

User accounts and client nodes are identified exclusively by an anonymized, high-entropy Crockford Base32 string:

XXXX-XXXX-XXXX (e.g., 9K2M-7PQ4-W8RT)

Key Design Properties

  • Zero-Email & Passwordless: User authentication relies on biometric Passkeys (WebAuthn / FIDO2) or OAuth2 identity providers requesting zero email scopes.
  • Blind Identity Hashing: Provider subject IDs and license keys are transformed into deterministic blind hashes (HMAC-SHA256) before database persistence.
  • Human-Friendly Display: Segmented into three 4-character blocks for support communication and license activation.
  • Ambiguity Normalization: Readily handles visual entry errors by automatically mapping visually similar characters (I and L map to 1, O maps to 0), while strictly excluding U to prevent unintended words.

2. Zero-Knowledge IP Lease Tracking

Under the BSL 1.1 licensing model (Free Tier limit of 2 concurrent stream views, or configured Pro quotas), the system regulates simultaneous active streams without storing raw IP addresses.

[Local Streaming Client]
│ (Stream Request: 192.0.2.10)
▼
[Irreversible Blind Hash] ──► HMAC-SHA256(Client_IP + License_Key)
│
▼
[Volatile Sliding Lease]
• 300s Rolling Heartbeat
• Instant Eviction on Idle

Concurrency Enforcement Model

  1. Blind IP Indexing: When a playback client connects, its IP address is combined with the license key and transformed through a one-way cryptographic hash. Cleartext network addresses are never stored in databases or transferred across network boundaries.
  2. Rolling Leases (300s TTL): Active leases expire automatically within 300 seconds if the streaming client disconnects or pauses playback.
  3. Graceful Limit Handling: If active connections reach the allowed threshold, additional concurrent playback attempts receive a concurrency_limit_exceeded status while allowing active sessions to continue undisturbed.

3. Playback & Content Privacy Guarantees

  • Zero Content Inspection: Pluvira does not log, inspect, or aggregate playback titles, viewing histories, or user M3U streaming URLs.
  • Mere Conduit Transport: Remote management sessions via WebRTC operate as blind, end-to-end encrypted tunnels (AES-256-GCM), preventing third parties or signaling relays from inspecting application data.

4. Customer Portal & Self-Service Lease Recovery

  • Zero-Knowledge Portal: Authenticating to https://pluvira.com/portal via Passkeys or OAuth2 extracts the blind subject hash (HMAC-SHA256(sub, PEPPER)), presenting active licenses without exposing user identity.
  • Session Lease Purge: If a home container restarts abruptly while active IP leases remain, users can trigger an instant lease reset (POST /api/v1/portal/licenses/{lic}/reset-leases) to unblock playback immediately.