Healthcare

File sharing built for protected health information — with an honest compliance story.

HIPAA is a programme, not a product badge. Here is precisely what our architecture contributes to the technical safeguards, and what we do not currently offer.

Encryption strong enough that a breach of our infrastructure is not a disclosure of your patients' data.

For clinics, therapists, allied-health practices, digital-health startups and healthcare consultants exchanging clinical documents.

Built for confidentiality

Encrypted on the device

Documents and images are sealed before upload with XChaCha20-Poly1305. Our servers never receive plaintext or a key to it.

Access as cryptography

Each authorised person holds their own sealed key envelope; removing someone rotates the rest.

Access logging

An append-only trail of grants, revocations, share creation and access events, exportable for your own documentation.

Time-limited external sharing

Links to patients, referrers or insurers can require a passphrase, expire and be revoked.

Works in a clinic

Desktop, mobile and web with an encrypted offline cache, passkey sign-in and device trust review.

Deletion you can evidence

Explicit deletion with a 30-day trash window, so retention decisions are deliberate.

What we do not claim

We do not currently sign Business Associate Agreements, and we do not hold SOC 2 or ISO 27001 certification. Any vendor implying that a tool alone makes you HIPAA compliant is describing marketing, not the rule. If a BAA is mandatory for your use case today, we will tell you plainly that we are not yet the right fit, and our compliance page tracks where this stands.

What the architecture genuinely contributes

The HIPAA Security Rule asks for access control, audit controls, integrity and transmission security. Client-side encryption with per-person key envelopes addresses access control in the strongest available form; authenticated encryption addresses integrity; an append-only log addresses audit controls; and content that is ciphertext before it leaves the device addresses transmission security beyond the transport layer.

Where teams usually leak PHI

Not through cryptography, but through habits: attachments sent to the wrong address, images kept in a consumer photo app that scans them, a shared login for the front desk, an ex-contractor still in a folder. Per-recipient links, per-person keys, passkeys and revocation address each of those directly.

Frequently asked questions

Will you sign a BAA?

+

Not today. We would rather say that than imply otherwise. Our compliance page documents the current state and what is planned.

Is encryption alone enough for HIPAA?

+

No. HIPAA covers administrative, physical and technical safeguards, workforce training, risk analysis and agreements with vendors. A zero-knowledge tool strengthens the technical layer; it does not replace the programme.

Can staff share one account?

+

They should not, and the design discourages it: each person gets their own identity, their own key envelopes and their own entries in the audit trail, which is what makes access logging meaningful.

Can DRIVUNO read our documents or messages?

+

No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need an IT team to deploy it?

+

No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.

What certifications do you hold today?

+

We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.

What happens if someone leaves the firm?

+

Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.

What if a user loses their password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.

Is there a free plan to evaluate it?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload