Microsoft Teams alternative

The Teams-style workspace your provider cannot read.

Channels, threads, mentions, file drops, calls and screen sharing — with every message and attachment sealed on your device before it leaves it.

Keep the way you work. Remove the party that can read it.

For legal, healthcare, finance, security and creative teams that need teams-grade usability for work covered by privilege, professional secrecy or an nda.

Built for confidentiality

Familiar collaboration patterns

Channels, threads, mentions, reactions, pinned messages, tasks and file drops — nothing exotic to learn.

Sealed on the device

Messages and attachments are encrypted with XChaCha20-Poly1305 under keys wrapped per member with X25519, derived locally with Argon2id.

Search without a readable server

Blind-index HMAC search is computed on your machine, so you can still find a message from six months ago without a server ever seeing its text.

A real encrypted drive behind the chat

My Drive, Team Drive with per-member sealed folder keys, Photos and encrypted mail — one key model instead of two half-secured systems.

Calls and screen sharing

Peer-to-peer audio, video and screen sharing over DTLS-SRTP, with a relay mode when you prefer not to expose participant IPs.

Cryptographic offboarding

Removing a member rotates room and folder keys instead of flipping a permission flag.

Why Teams is readable by design

Microsoft Teams encrypts data in transit and at rest with service-managed keys, and offers end-to-end encryption for specific one-to-one call scenarios. Channel messages and files are not end-to-end encrypted, because compliance search, retention, legal hold, data loss prevention and assistant features all require the platform to read content. That is a deliberate, well-documented trade — and it is the trade we made in the opposite direction.

The split most teams should make

Keep Teams for company-wide coordination and anything under a tenant-wide retention obligation. Move the confidential surface — client matters, deal work, patient detail, incident response, unreleased product — into a workspace where disclosure is technically unavailable to the provider. A split by obligation is far easier to defend internally than an all-or-nothing migration.

What we can and cannot see

We can see that an account exists, which rooms it belongs to, when messages were sent and how large the ciphertext is. We cannot see message text, file contents, file names, channel names or mail bodies. Security events are logged immutably as metadata, never as content.

Frequently asked questions

Can DRIVUNO read our messages or files?

+

No. Content is encrypted on your device before upload. Account keys are derived locally with Argon2id, room and folder keys are wrapped per member with X25519, and payloads are sealed with XChaCha20-Poly1305. Our servers store ciphertext and wrapped keys.

How is that different from 'encrypted in transit and at rest'?

+

Transit and at-rest encryption use keys held by the provider, which is why server-side search, previews, scanning and administrative export are possible. Client-side encryption removes the provider from the set of parties able to read content.

What do we lose by moving to zero-knowledge?

+

Provider-side full-text search over document contents, universal server-generated previews, content AI on your data, administrative content export, and password resets that recover data. Search runs on device-side blind indexes and recovery relies on a recovery kit you keep offline.

What happens when someone leaves?

+

Removal revokes their sealed copy of the room or folder key and triggers rotation, so future content is sealed under a key they never held.

How does external sharing work?

+

Public links carry key material in the URL fragment, which browsers never transmit to a server, are gated by a passphrase and expire within 24 hours at most. Links can be revoked earlier and view counts capped.

Do we have to migrate everything at once?

+

No, and most teams should not. Move the confidential surface first — client work, matters, deals, personal data, unreleased product — and keep general coordination where it is until the pilot proves out.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload