Hidden services keep getting busted, so onion routing must be broken.
What happened
The takedowns we have records for come down to operator mistakes: servers that were also reachable at a normal internet address, misconfigured software that printed its real address in an error page, operators reusing a personal email address from years earlier, third-party scripts, informants. Where court documents exist, they describe exactly these failures. None of them describes anyone breaking Tor's encryption.
What Aphotic does
Aphotic is built on the assumption that someone will try those mistakes against it. The server has no normal internet address that could leak. It sits on an internal-only network where the Tor process is the one thing that can reach the outside world, and every incoming port is shut. Replies carry no identifying headers, and even the health check gives away no version number. If a machine were seized anyway, it would hold scrambled messages, public keys, pseudonymous IDs and group memberships, and the order records of the license shop, none of which name a person. The privacy policy lists every field.