Traditional clouds can read you.
DRIVUNO is designed to never have that power.
Not a cloud — your private encrypted vault.
Professional files, confidential projects or personal data — encrypted on your device before they even reach our servers. Only your keys can unlock them.
Desktop, phone, browser — the same sealed vault.
Install DRIVUNO as a real app on Mac, Windows, iPhone or Android — or just open it in any browser. Your keys travel with you, never with us: on set, in a hotel, on a plane or at the studio, you unlock the same encrypted workspace — files, Rooms, calendar and team drives, in sync and unreadable to anyone else.







Talk. Share. Nobody reads it.
DRIVUNO Rooms replaces Slack and Teams with real end-to-end encryption: messages, files and calls are sealed on your device before they leave it.
- Messages sealed with XChaCha20-Poly1305 — the server stores unreadable bytes
- Drop any files directly in messages — they land encrypted in your Team Drive
- Peer-to-peer audio & video calls — media never transits our servers
- Read receipts, edits and @mentions — full control over every conversation
- Every shared file is auto-filed in the room's Team Drive — encrypted before it leaves your device
Final 4K master is in — colour pass approved by the client.


Perfect. Anything I need to send to the studio tonight?
Everything you drop here lands straight in the room's Team Drive — already encrypted.

A real workspace — sealed on your device.

Channels, files, calendar, docs
Everything a studio runs on, in one encrypted channel — with its own Team Drive attached.
All your passwords, API keys, cards and licences — in one place, safe for you and your team.
Stop hunting for logins in emails, chats and sticky notes. Keep everything in one vault, and share exactly what your team needs in seconds — without ever sending a password by message.
Everything in one place
Passwords, API keys, bank cards, software licences, private notes. Saved once, found instantly, on your computer and your phone.
Shared vaults for your teams
Create a vault for a team, a client or a project, invite the people who need it, and choose what each one can do: use, view, edit or manage.
Take access back in one click
Someone leaves the project? Remove them and their access disappears immediately — no passwords to change, no one left to chase.
Weak passwords, fixed for you
We tell you which passwords are weak, reused or caught in a leak — and create a strong new one for you in a single click.
Same protection as your files and your messages: everything is locked on your device before it leaves. Not DRIVUNO, not our hosting provider, no one else can open it.
Where others promise privacy, we enforce it by architecture.
Google, iCloud, Dropbox, OneDrive — they all technically can read your files. DRIVUNO cannot. Your data is encrypted on your device, before a single byte is sent. Our servers see only binary noise.
- They hold the decryption keys
- Automatically scan your content (AI, moderation)
- Forced to comply with authorities
- A database leak = your files in clear text
- Terms allow advertising-driven exploitation
- You are the only holder of the keys
- No scanning, no AI, no access to your content — thanks to a zero-knowledge architecture
- Even with server access, data stays encrypted and unreadable without user keys
- A leak = only random bytes
- No advertising. No data resale. No exploitation of your content.
Zero-knowledge architecture
Your files, file names, messages and recipients are encrypted before sending. No one can read them — not even our engineers.
Internal encrypted mailbox
A 100% end-to-end encrypted mailbox, exclusively between DRIVUNO users. Keys sealed per recipient.
Protected view
Protected View restricts download and copy functions in the interface and can apply expiration or watermarking. As with any content displayed on a screen, absolute protection against external capture cannot be guaranteed.
Local recovery kit
Your recovery key is generated and shown only on your device. Lose it, we can do nothing — that is precisely the point.
Modern cryptography
Argon2id for key derivation, X25519 for sealed envelopes, XChaCha20-Poly1305 for content. Built on modern, recognized cryptographic standards.
European sovereignty
Infrastructure hosted in the EU, GDPR compliant, independent security assessment planned. Your data never leaves the territory.
Eight layers. Every one of them has to hold.
Encryption alone is not security. A vault is only as strong as the weakest link around it — the code in your browser, the keys you exchange, the access rules on every request. Here is what stands between an attacker and your data.
01Nothing leaves your device readable
Files, photos, messages, calls, notes, documents and calendars are encrypted on your device before they are sent. We operate the service on ciphertext we cannot open.
02We do not hold your keys
Your key is derived from your password on your device and never transmitted. There is no master key, no escrow, and no internal procedure that reveals your content — not for us, not for a court order, not for an attacker inside our systems.
03A failed check blocks, it does not warn
If the app running in your browser is not the app we published, your vault refuses to open and your key is never created. Most services show a warning you can click past. We stop.
04Your contacts' keys are authenticated
Before anything is encrypted for someone else, their key is verified against a signed, append-only history. A key that cannot be authenticated is rejected — so no one can quietly slip themselves into a conversation.
05Access rules are enforced and re-tested continuously
Every request is checked against per-user rules at the database itself, not just in the interface. Hundreds of automated tests re-attack those rules on every single change, and a failure blocks the release.
06Even the shape of your data is hidden
Encryption hides content, but sizes and patterns leak. We minimise what is stored, and pad message content so exact lengths cannot be observed.
07Account access is hard to steal
Passkeys, two-factor authentication, step-up confirmation for sensitive actions, session inactivity locking, alerts on unusual sign-ins and one-tap revocation of any device.
08Losing our infrastructure does not lose your data
Encrypted, immutable off-site snapshots and multi-provider storage. Whoever holds the disks — including us — holds nothing they can read.
We publish what each layer does and, just as importantly, what it does not do. No security page that only lists strengths is telling you the truth.
Every control in your hands
Not a settings page you never open — a cockpit. Devices, sessions, passkeys, recovery, residency and lockdown, all visible, all yours.

Security Center
XChaCha20 + Argon2id, trusted devices and live code verification — at a glance.
How your data is protected — in three steps
Your data, protected even if a whole provider goes down.
DRIVUNO does not just store your encrypted files — it replicates them. Every vault has a primary copy and an immutable encrypted backup on a separate provider, in a different region (and a different continent when possible). If one provider is banned, breached, or simply offline, your data stays available and stays unreadable.
Primary encrypted storage
Files are encrypted on your device, then stored as ciphertext on Backblaze B2 (EU) with automatic fallback to Supabase Storage.
Hourly immutable backups
Snapshots are wrapped with a separate X25519 master key and pushed to Backblaze B2 with Object Lock — 30 days of write-once retention. Ransomware and account bans cannot delete them.
Cross-continent redundancy
EU primary + JP/EU secondary candidates wired in (OVHcloud, Scaleway, Hetzner, Sakura, IIJ, GMO). Sovereignty modes — Standard, EU Safety, JP Safety, Hybrid, Emergency — switch routing without redeploying.
Provider-agnostic by architecture
Storage, database, payments, auth, email, analytics and CDN all sit behind interfaces. If a provider has to be replaced, ciphertext migrates — plaintext is never reconstructed server-side.
A full workspace, sealed end to end
Dashboard, private drive, team drives, photos and automation — all decrypted on your device, never on our servers.

Your vault at a glance
Files, unread messages, tasks and a unified calendar — every line decrypted on this device.
Your PC / Mac folders,
backed up live 24/7,
in total encryption.
Point DRIVUNO at one folder, several folders, or an entire disk. Every new file and every change is encrypted on your device, then cloned to your vault in real time. You keep the only keys.
- 1 folder or many — even a full external disk
- Live 24/7 sync from PC / Mac
- Encrypted on your device before upload
- Version history kept — nothing is overwritten

Point it at a folder or a whole drive. It never stops protecting it.
Live Clone watches your local folders and mirrors every change into your vault — encrypted on your device before it leaves, versioned so nothing is ever overwritten or lost. No sync client to trust, no plaintext copy anywhere, no manual backup to remember.
- Always-on, silent, incremental
- Every version kept — ransomware-proof
- Encrypted before upload, keys stay with you
- Restore any file on any device
How major clouds handle your files.
Most providers encrypt files after they reach their servers — meaning the provider technically holds the keys and can access content under its own policies. DRIVUNO encrypts on your device, before anything leaves it, so the provider cannot decrypt what you store.
| Provider | Zero-knowledge | Client-side encryption | Provider can't decrypt | No plaintext scanning | You hold the keys | Immutable backup | E2EE chat, calls & docs | EU/JP sovereignty | Passkeys & ZK recovery |
|---|---|---|---|---|---|---|---|---|---|
Google Drive Provider-managed encryption; content readable by provider-side systems. | |||||||||
Dropbox Server-side keys held by Dropbox; provider-side content analysis possible. | |||||||||
OneDrive Microsoft manages keys; server-side scanning is documented. | |||||||||
iCloud Drive E2EE only with Advanced Data Protection; default keeps some keys server-side. | |||||||||
WeTransfer Provider-managed encryption in transit and at rest; content review possible. | |||||||||
Slack Workspace content accessible to provider and admin systems. | |||||||||
DRIVUNOYou Encrypted on your device (Argon2id + X25519 + XChaCha20-Poly1305): drive, photos, chat, calls, docs & whiteboards. Hourly Object-Lock backups, EU/JP regions, passkeys + offline recovery kit. |
Provider-managed encryption; content readable by provider-side systems.
Server-side keys held by Dropbox; provider-side content analysis possible.
Microsoft manages keys; server-side scanning is documented.
E2EE only with Advanced Data Protection; default keeps some keys server-side.
Provider-managed encryption in transit and at rest; content review possible.
Workspace content accessible to provider and admin systems.
Encrypted on your device (Argon2id + X25519 + XChaCha20-Poly1305): drive, photos, chat, calls, docs & whiteboards. Hourly Object-Lock backups, EU/JP regions, passkeys + offline recovery kit.
A vault for every use.
Zero-knowledge encryption, internal mailbox and protected sharing included in every plan. Save 17% with annual billing.
Starter
Get started securely
Billed $99/year · save 17% · 250 GB
- Zero-knowledge AES-256 encryption
- 250 GB encrypted storage
- DRIVUNO Rooms — E2EE chat, threads & files
- Encrypted audio & video calls (P2P)
- Encrypted Notes, Docs & Sheets
- Shared Calendar with smart reminders
- Unlimited Photos zone (within quota)
- Protected shares (one-view, expiry, watermark)
- Unlimited end-to-end mailbox
- Standard support
Premium
Most popular
Billed $199/year · save 17% · 600 GB
- Everything in Starter
- 600 GB encrypted storage
- Live Clone — continuous folder & disk backup
- Flowboard & encrypted tasks
- Team Drive with per-member sealed keys
- Hardware 2FA (YubiKey, Titan)
- Unlimited encrypted folders
- Advanced audit log
- Multi-channel secure recovery
Business
For teams (5 users min.)
Billed $149/user/year · save 17% · 400 GB / user · from 5 users
- Everything in Premium
- 400 GB per user
- From 5 users
- Shared Team Drives & ROOM folders
- Org-wide Rooms, Calendar, Docs & tasks
- SAML SSO / SCIM
- Enterprise audit log
- Granular admin controls
- 99.95% SLA & dedicated support
VAT handled automatically · Cancel anytime · Storage add-ons available from your billing area
Everything you want to know before trusting a vault.
Encryption, Rooms, shared drives, Live Clone, sovereignty and billing — in plain language.









