Always host software outside of US or *eyes jurisdictions. Think Truecrypt.
What happened to Truecrypt? Isn't that the one with the fundamental flaw that means everything it encrypted is trivial to unlock today? EDIT: this is a genuine question, I thought it had been unmaintained for ages and vulnerabilities had been found. My memory betrays me?
> Using TrueCrypt is not secure as it may contain unfixed security issues.
Not Secure As. Whether this holds any weight, only the maintainers would know.
More info: https://grahamcluley.com/truecrypt-hidden-message/