Zero-PII Identity & Concurrency Model
Pluvira is architected around strict privacy-by-design and zero-knowledge principles. The system enforces concurrency quotas and licensing entitlements without tracking personal identities, media consumption, or cleartext network addresses.
1. Zero-PII User Identification
User accounts and client nodes are identified exclusively by an anonymized, high-entropy Crockford Base32 string:
XXXX-XXXX-XXXX (e.g., 9K2M-7PQ4-W8RT)Key Design Properties
- Zero-Email & Passwordless: User authentication relies on biometric Passkeys (WebAuthn / FIDO2) or OAuth2 identity providers requesting zero email scopes.
- Blind Identity Hashing: Provider subject IDs and license keys are transformed into deterministic blind hashes (
HMAC-SHA256) before database persistence. - Human-Friendly Display: Segmented into three 4-character blocks for support communication and license activation.
- Ambiguity Normalization: Readily handles visual entry errors by automatically mapping visually similar characters (
IandLmap to1,Omaps to0), while strictly excludingUto prevent unintended words.
2. Zero-Knowledge IP Lease Tracking
Under the BSL 1.1 licensing model (Free Tier limit of 2 concurrent stream views, or configured Pro quotas), the system regulates simultaneous active streams without storing raw IP addresses.
[Local Streaming Client] │ (Stream Request: 192.0.2.10) ▼ [Irreversible Blind Hash] ──► HMAC-SHA256(Client_IP + License_Key) │ ▼ [Volatile Sliding Lease] • 300s Rolling Heartbeat • Instant Eviction on IdleConcurrency Enforcement Model
- Blind IP Indexing: When a playback client connects, its IP address is combined with the license key and transformed through a one-way cryptographic hash. Cleartext network addresses are never stored in databases or transferred across network boundaries.
- Rolling Leases (300s TTL): Active leases expire automatically within 300 seconds if the streaming client disconnects or pauses playback.
- Graceful Limit Handling: If active connections reach the allowed threshold, additional concurrent playback attempts receive a
concurrency_limit_exceededstatus while allowing active sessions to continue undisturbed.
3. Playback & Content Privacy Guarantees
- Zero Content Inspection: Pluvira does not log, inspect, or aggregate playback titles, viewing histories, or user M3U streaming URLs.
- Mere Conduit Transport: Remote management sessions via WebRTC operate as blind, end-to-end encrypted tunnels (AES-256-GCM), preventing third parties or signaling relays from inspecting application data.
4. Customer Portal & Self-Service Lease Recovery
- Zero-Knowledge Portal: Authenticating to
https://pluvira.com/portalvia Passkeys or OAuth2 extracts the blind subject hash (HMAC-SHA256(sub, PEPPER)), presenting active licenses without exposing user identity. - Session Lease Purge: If a home container restarts abruptly while active IP leases remain, users can trigger an instant lease reset (
POST /api/v1/portal/licenses/{lic}/reset-leases) to unblock playback immediately.