Business

Business storage where access is enforced by keys, not by a permissions table.

Seats, shared drives, admin controls and audit logs — with encryption that happens before anything leaves an employee's device.

The only people who can read company data are the people you gave keys to.

For companies from five to several hundred people that treat their documents as a liability if exposed.

Built for confidentiality

Organisations and seats

Invite by email, manage seats, pool storage across the team and see who has access to what.

Team drives with sealed keys

Every member of a drive receives their own sealed envelope of the folder key; removal rotates the rest.

Audit trail

Append-only records of membership, sharing and access events for internal review.

Controlled external sharing

Protected links with expiry, passphrase, watermark and revocation for clients and vendors.

Passkeys and MFA

Passkeys, TOTP, step-up verification and reviewable device trust across the organisation.

Encrypted backups

Hourly encrypted snapshots to immutable object storage, with restore tooling.

Permissions tables versus key envelopes

In a conventional cloud, an access-control list decides who may decrypt, and the decryption itself happens on a server that can always do it. In a zero-knowledge system, the ability to decrypt is the access control: no envelope, no key, no read — regardless of a bug, a misconfiguration or an administrator's mistake.

Offboarding that actually terminates access

The riskiest week for company data is the one after someone leaves. Removing a member here revokes their session, rotates the remaining key envelopes for their drives and writes the change to the audit trail, in one operation.

Cost of consolidation

Replacing separate storage, chat, calls, mail and password tooling with one encrypted workspace usually reduces both spend and the number of places a copy of your data can exist.

Frequently asked questions

Can an administrator read employee content?

+

No. Administrators manage membership, seats and billing. They cannot decrypt content they were not given a key envelope for, and every membership change is logged.

What happens if an employee loses their laptop?

+

Revoke the device from the session list; its cached material becomes useless without credentials, and passkey or password re-authentication is required to reconnect.

Can DRIVUNO read our documents or messages?

+

No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need an IT team to deploy it?

+

No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.

What certifications do you hold today?

+

We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.

What happens if someone leaves the firm?

+

Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.

What if a user loses their password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.

Is there a free plan to evaluate it?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload