Privacy by Architecture, Not Policy.
Nivara combines state partitioning, Tor-derived anti-fingerprinting, native content filtering, and encrypted DNS to eliminate commercial surveillance at the network layer.
Select Your Privacy Tier
Nivara gives you complete control over the tradeoff between extreme fingerprint masking and specialized web app compatibility.
Everyday Protection
Perfect balance for daily browsing. Blocks all cross-site trackers, isolates cookies, and randomizes canvas hashes while maintaining 99.9% site compatibility.
- Total Cookie Protection
- EasyList / EasyPrivacy Blocking
- Canvas Hash Randomization
- HTTPS-First with fallback
Hardened Shield
Enforces full Tor Resist Fingerprinting (RFP), letterboxing window sizes, standardized font whitelisting, and strict HTTPS-Only enforcement.
- Tor RFP Fingerprint Masking
- UTC Timezone Normalization
- Strict HTTPS-Only (No HTTP)
- Encrypted Client Hello (ECH)
Maximum Defense
Designed for activists, journalists, and high-threat environments. Session-only storage (auto-wiped on tab close), WebGL disabled, and zero local cache.
- Ephemeral RAM Storage Only
- WebGL & Web Audio Disabled
- WebRTC Completely Disabled
- Strict Certificate Pinning
14 Core Architectural Defenses
Technical specifications of the privacy layers compiled into Nivara Browser.
1. Total Cookie Protection (State Partitioning)
Cookies, IndexedDB, and local cache are segregated by top-level origin. Third-party advertising trackers loaded on multiple websites are placed in isolated containers and cannot join your identity across domains.
2. Anti-Fingerprinting (Tor RFP Engine)
Standardizes canvas noise, font enumeration lists, screen geometry, CPU core counts, and timezones to group all Nivara users into a uniform, non-unique crowd fingerprint.
3. Native Content & Ad Blocking
Evaluates network requests natively in C++/Rust before sockets open. Blocks advertising scripts, tracking pixels, and cryptominers without accepting paid whitelists.
4. Encrypted DNS & ECH Support
Encrypts domain lookups over DoH/DoT and hides Server Name Indication (SNI) using TLS 1.3 Encrypted Client Hello, preventing ISPs from spying on websites you open.
5. WebRTC Local IP Leak Prevention
Limits WebRTC ICE candidate discovery to default public network interfaces, blocking rogue scripts from discovering your private LAN IP address (`192.168.x.x`).
6. Referrer Stripping & CNAME Uncloaking
Strips sensitive tokens and search query strings from cross-origin HTTP Referer headers, and unmasks trackers disguising themselves under first-party CNAME subdomains.