Authentication

Sign in with a key that never leaves your device.

Passkeys and discoverable credentials replace typed secrets with an origin-bound signature — nothing to phish, nothing to replay, nothing to read from an SMS.

Authentication that proves who you are, without ever revealing what you hold.

For individuals and teams who want phishing-resistant sign-in without weakening the zero-knowledge model that protects their data.

Built for confidentiality

Discoverable credentials

Your authenticator knows which account it holds for this site, so you can sign in without typing an identifier.

Origin-bound by design

A lookalike domain cannot trigger a signature for the real site, which is what makes passkeys phishing-resistant.

Step-up on what matters

New device approval, key rotation and administrative actions ask for fresh proof, while day-to-day use stays fast.

Trusted devices

Approve a device once and choose how long the session stays trusted, with sliding renewal on active use.

Login and decryption kept separate

A passkey proves identity; your data is opened by an account key derived from your password on your own device.

Recovery you control

A printable Recovery Kit with a QR code lets you rebuild access offline, without ever giving us the ability to do it for you.

Discoverable vs non-discoverable

A discoverable credential (historically a resident key) is stored on the authenticator with enough information to identify the account, enabling usernameless login. A non-discoverable one requires the site to name the credential first, so you must identify yourself before authenticating.

What the server stores

A public key and a credential identifier. The private key stays inside the authenticator, protected by your device biometric or PIN, and is never transmitted.

Why a strong login cannot rescue a lost password

Authentication and decryption are deliberately separate concerns. If a login could restore your files, someone else's login could too. Register two authenticators and keep the Recovery Kit offline.

Frequently asked questions

What is a discoverable credential?

+

A WebAuthn credential stored on your authenticator together with account information, which lets the browser offer the right account without you typing an identifier.

Do passkeys replace my DRIVUNO password?

+

For signing in, yes. Your password still derives the key that decrypts your data on your device, which is why it cannot be reset by us.

What if I lose the device holding my passkey?

+

Register a second authenticator on a different device, and keep your Recovery Kit offline. Recovery design matters more than the login mechanism itself.

Can DRIVUNO read this content?

+

No. Everything is encrypted on your device with XChaCha20-Poly1305, using keys derived locally from your password with Argon2id and wrapped per member with X25519. Servers store ciphertext and sealed key envelopes only.

Is there a free plan?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans.

What happens if I lose my password?

+

Because we cannot read your data, we cannot reset it for you. Create a Recovery Kit — a printable PDF with a QR code — and store it offline. That is the same property that stops anyone else from reading your account.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload