Client-Side Encryption: Protecting User Data You Never See
Most web applications that handle sensitive data follow a familiar pattern: collect it, transmit it over TLS, store it in a database, and promise users you will look after it. The problem with this model is that you -- the site operator -- can see everything. Your database administrators can query it. A breach exposes it. A subpoena compels it. A rogue employee exfiltrates it.