External sharing

Share links that expire, watermark and report back.

A public link is the weakest point of most workspaces. These ones carry a passphrase, a deadline, a view budget and a log — and the server still cannot read the file.

No permanent links. No silent access. No readable copy on our side.

For anyone sending confidential material to people outside their organisation.

Built for confidentiality

Key in the fragment, passphrase on top

The decryption key travels in the URL fragment, which browsers never send to servers, and a passphrase derived with Argon2id gates the open.

Automatic destruction

Every public link carries a maximum lifetime and is destroyed automatically when it runs out.

View-once and view budgets

Cap a link at one open or a fixed count, and watch the counter in real time.

Watermarked viewer

Display sensitive documents and media in a protected viewer that stamps context onto the view.

Instant revocation

Kill a link the moment a deal falls through or a partner changes; the action is recorded.

Access log

Creation, opens, expiry and revocation are appended to a tamper-evident trail.

Why link security is usually theatre

Most 'secure links' are ordinary URLs with a permission check on a server that also holds your plaintext. If that server is breached, misconfigured or compelled, the link controls are irrelevant. Here, the file is ciphertext regardless of what the link layer does.

Designing an external hand-off

One recipient, one link, one expiry, one passphrase sent through a different channel. That single habit removes the majority of accidental exposure, and makes leaks attributable when they happen.

What logs can and cannot tell you

Logs record access events, not intent, and cannot see content. That is deliberate: it gives you evidence for an investigation without creating a new pool of readable data to protect.

Frequently asked questions

Can you recover a link's password for a recipient?

+

No. The passphrase never reaches us; resend the link with a new one instead.

Does the recipient need an account?

+

No, any modern browser works. Decryption happens in the page.

Can DRIVUNO read our messages, files or builds?

+

No. Everything is encrypted on the device before it leaves it, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need a technical team to run it?

+

No. There is nothing to self-host and nothing to configure: you create an account, invite people by email, and encryption happens transparently in the browser and apps. Zero-knowledge here is the default, not an expert mode.

Is there a free plan?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate the workflow before moving a studio onto it.

What happens if someone leaves the team?

+

Removing a member revokes their access and rotates the remaining key envelopes, so their old copy of the key stops opening anything new. Every membership change is written to an append-only audit trail.

What if we lose a password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to keep offline. That is the same property that stops anyone else, including us, from reading your workspace.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload