Google Workspace alternative

For the part of your work that must not be readable.

An encrypted drive, team folders, rooms with calls and an encrypted mailbox — one key model, derived on your device.

Convenience where it is harmless. Zero-knowledge where it matters.

For organisations on google workspace or microsoft 365 that need a confidential surface without abandoning their calendar and meeting stack.

Built for confidentiality

Encrypted drive and team folders

Client-side encryption, versioning, trash, and folder keys sealed per member with rotation on removal.

Rooms with calls

Channels, threads, mentions, file drops, peer-to-peer audio, video and screen sharing — all sealed on the device.

Encrypted mailbox

Message bodies that do not sit readable on a server, with client-side incremental search and your own sending identities.

External exchange with expiry

Passphrase-gated links, key material in the fragment only, and a hard 24-hour maximum lifetime.

Hardware-backed access

Passkeys and TOTP, device trust with sliding renewal, and a metadata-only immutable audit trail.

Continuity you can prove

Recovery kits, hourly encrypted snapshots to independent immutable storage and tested one-click restore.

Nobody replaces a suite in one step

Google Workspace and Microsoft 365 bundle identity, mail, calendars, documents, storage, chat and meetings, and their best features exist because the provider can read your content. A credible plan moves the parts where confidentiality is the requirement, and keeps the parts where convenience is: calendars, external scheduling, public documents and anything under a tenant-wide retention obligation.

One boundary rule your team will actually follow

If it would harm a client, a case, a deal or a person to have it read, it lives in the encrypted workspace. Rules that fit in a sentence survive busy quarters; matrices do not.

What this changes in a security questionnaire

Three answers change the shape of a vendor risk assessment: the provider cannot read content, access is per-member and revocation is cryptographic, and backups are encrypted and independently restorable. Those are architectural statements, not policy commitments.

Frequently asked questions

Can DRIVUNO read our messages or files?

+

No. Content is encrypted on your device before upload. Account keys are derived locally with Argon2id, room and folder keys are wrapped per member with X25519, and payloads are sealed with XChaCha20-Poly1305. Our servers store ciphertext and wrapped keys.

How is that different from 'encrypted in transit and at rest'?

+

Transit and at-rest encryption use keys held by the provider, which is why server-side search, previews, scanning and administrative export are possible. Client-side encryption removes the provider from the set of parties able to read content.

What do we lose by moving to zero-knowledge?

+

Provider-side full-text search over document contents, universal server-generated previews, content AI on your data, administrative content export, and password resets that recover data. Search runs on device-side blind indexes and recovery relies on a recovery kit you keep offline.

What happens when someone leaves?

+

Removal revokes their sealed copy of the room or folder key and triggers rotation, so future content is sealed under a key they never held.

How does external sharing work?

+

Public links carry key material in the URL fragment, which browsers never transmit to a server, are gated by a passphrase and expire within 24 hours at most. Links can be revoked earlier and view counts capped.

Do we have to migrate everything at once?

+

No, and most teams should not. Move the confidential surface first — client work, matters, deals, personal data, unreleased product — and keep general coordination where it is until the pilot proves out.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload