Storage for clinical material that no provider system can open.
Imaging, reports, consent forms and correspondence are encrypted on the device. What we host cannot be previewed, indexed or classified by us.
“Patient material that stays between the people treating the patient.”
For private practices, multi-site clinics, allied health, research teams and health-tech companies handling sensitive records.
Built for confidentiality
Images without scanning
Thumbnails are generated on your device. No classifier ever sees clinical imagery, so there is no automated review and no content-based account action.
Per-team encrypted drives
Separate drives per site, department or study, each with keys sealed per member.
Encrypted correspondence
Internal discussion and referral notes stay in an encrypted channel rather than a readable chat product.
Versioning and recovery
Restore earlier versions and deleted items within a 30-day window, without provider access to content.
Strong sign-in
Passkeys, TOTP and reviewable device trust, so a lost tablet is a revocation rather than an incident.
Documented locations
Published storage regions and subprocessors for your vendor assessments.
Consumer clouds are a poor fit for clinical files
Consumer photo and storage products classify content automatically and can restrict accounts on the basis of that classification. Clinical imagery is exactly the sort of material that triggers such systems, with consequences ranging from embarrassing to catastrophic. A zero-knowledge system has nothing to classify.
Access control that survives staff turnover
Locum cover, rotating residents, part-time administrators: healthcare teams change constantly. Per-person key envelopes make onboarding and offboarding a cryptographic operation with an audit entry, instead of a folder-permission review nobody has time to run.
Honest limits
We do not sign BAAs today and we hold no certification yet; see our compliance page. We also cannot recover data for you if credentials and the offline Recovery Kit are both lost — the same property that keeps us out also keeps us from helping in that scenario.
Frequently asked questions
Can you scan or view uploaded medical images?
+
No. Images are encrypted before upload and thumbnails are produced locally. We host ciphertext.
Can we share results with a patient?
+
Yes, through a protected link with a passphrase and an expiry, without the patient creating an account.
Can DRIVUNO read our documents or messages?
+
No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.
Do we need an IT team to deploy it?
+
No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.
What certifications do you hold today?
+
We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.
What happens if someone leaves the firm?
+
Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.
What if a user loses their password?
+
Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.
Is there a free plan to evaluate it?
+
Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.