← Blog
Comparisons6 min read

pCloud encrypted folder: how add-on encryption compares to a fully encrypted vault

An encrypted folder protects what you remember to put in it. Here is the practical difference between add-on encryption and an architecture where everything is sealed by default.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

The pattern: an encrypted room inside a readable house Several mainstream clouds — pCloud among the best known — offer client-side encryption for a designated folder, usually as a paid add-on, while the rest of the account stays under provider-managed encryption. Inside the special folder, the provider genuinely cannot read the content. Outside it, standard cloud rules apply.

That design is a real improvement over nothing. It also has structural consequences worth understanding before you rely on it.

Where the boundary leaks in practice - **Human sorting.** Protection depends on remembering to place each sensitive file in the right folder, every time, including the file someone else uploads. - **Feature asymmetry.** The encrypted area typically loses previews, in-browser editing, fast search or easy sharing, which pushes people to work outside it. - **Everything else stays readable.** Mail, chat, calendars, notes, shared links and passwords usually live outside the encrypted folder entirely. - **Account-level enforcement.** If content elsewhere in the account can be scanned, the account can still be actioned.

The alternative: no boundary to manage DRIVUNO applies the same model to the whole workspace. Files, photos, mail, Rooms messages, documents, tasks, calendar entries and passwords are encrypted on the device before upload with XChaCha20-Poly1305, keys wrapped with X25519 and derived from your password with Argon2id. There is no "protected folder" because there is no unprotected one.

Search still works through blind indexes computed on your device. Sharing works through per-recipient key envelopes rather than server-side permissions. Team folders seal a folder key per member and rotate it when someone leaves.

What to compare, feature by feature - Is encryption included, or an add-on tier? - Does it cover messaging and mail, or only file storage? - Can shared links expire automatically, and is the key kept off the server? - Are backups encrypted before they leave the platform? - Is there a documented recovery mechanism you control?

Migration in practice Export from the existing account, import in the browser so files are sealed as they arrive, then point Live Clone at your working folder so new work is protected without a decision. Keep the Recovery Kit offline.

An encrypted folder asks you to be disciplined. An encrypted architecture does not need you to be.

Try it in one click.

Three private surfaces. Same zero-knowledge architecture.

Encrypted on your device · upload in 1 click
Upload