Partition by partner, not by convenience
The most common structural mistake is one shared folder for all externals. Separate encrypted spaces per partner limit blast radius and make attribution possible when something surfaces publicly.
Concept art, source assets, captures, localisation kits, milestone builds and design documents move between a dozen organisations before launch. Each hop is a chance to lose control.
“One encrypted pipeline instead of ten uncontrolled hand-offs.”
For studios working with outsourcing partners, publishers, localisation vendors, marketing agencies and platform holders.
Source art, captures and packages transfer in resumable chunks with deduplication and verification.
Give each partner their own drive or room with its own membership, so an outsourcing studio never sees the publisher's material.
Passphrase, expiry, view budget and revocation on every external hand-off.
Show work in a protected viewer that stamps context onto what is displayed.
Feedback stays in the same encrypted workspace as the asset, instead of scattering across three chat products.
Version history and a 30-day trash mean an overwritten asset is not a crisis.
The most common structural mistake is one shared folder for all externals. Separate encrypted spaces per partner limit blast radius and make attribution possible when something surfaces publicly.
Vendors send back captures, bug reports and localised builds. If the return path is personal email, the material has already left your control. Give every partner an encrypted upload destination.
At the end of an engagement, remove the partner's members: keys rotate, links can be revoked in bulk and the audit trail records the closure.
No. Web access covers external collaborators; desktop and mobile apps are there for the people living in the workspace.
Public links carry a maximum lifetime that cannot be extended indefinitely, so 'forever links' are not an option to begin with.
No. Everything is encrypted on the device before it leaves it, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.
No. There is nothing to self-host and nothing to configure: you create an account, invite people by email, and encryption happens transparently in the browser and apps. Zero-knowledge here is the default, not an expert mode.
Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate the workflow before moving a studio onto it.
Removing a member revokes their access and rotates the remaining key envelopes, so their old copy of the key stops opening anything new. Every membership change is written to an append-only audit trail.
Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to keep offline. That is the same property that stops anyone else, including us, from reading your workspace.
Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.