External teams

External QA and partners, without permanent access to everything.

Outsourced QA is where scope creep meets access creep: a folder shared for one milestone quietly stays open for two years.

Access that ends when the engagement does.

For producers and studio it managing outsourced qa, co-development partners, localisation and marketing vendors.

Built for confidentiality

Scoped encrypted spaces

One drive or room per vendor, with membership and keys that do not overlap other partners.

Time-boxed access

Links expire on a schedule and memberships are removed at milestone close, with key rotation for the rest of the team.

Encrypted return path

Vendors upload captures, crash dumps and reports into the same encrypted space instead of emailing them.

Watermarked review

Anything displayed in the protected viewer carries watermarking, making a leaked screenshot attributable.

Evidence for your publisher

Append-only logs show exactly who had access and when it ended, without exposing content.

A channel per vendor

Encrypted chat with the vendor lives beside their files, and closes with the engagement.

Access creep is the quiet failure

Nobody plans to leave a vendor inside the pipeline forever. It happens because revoking access is manual, unlogged and spread across several products. Making revocation cryptographic and one-click removes the excuse.

Least privilege, expressed in keys

Rather than trusting a permission matrix, each vendor space has its own keys sealed to its own members. There is no configuration mistake that suddenly exposes the whole studio drive.

When something leaks anyway

Watermarking, per-recipient links and access logs turn 'somebody leaked it' into a short list of candidates, which is usually enough to end the leak and settle the contract question.

Frequently asked questions

Can we give a vendor upload-only access?

+

Yes — scope a space to the material they need and give them their own room and drive folder for returns.

Do we lose the audit trail because everything is encrypted?

+

No. Metadata events — membership, link creation, views, revocation — are logged; only content stays unreadable.

Can DRIVUNO read our messages, files or builds?

+

No. Everything is encrypted on the device before it leaves it, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need a technical team to run it?

+

No. There is nothing to self-host and nothing to configure: you create an account, invite people by email, and encryption happens transparently in the browser and apps. Zero-knowledge here is the default, not an expert mode.

Is there a free plan?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate the workflow before moving a studio onto it.

What happens if someone leaves the team?

+

Removing a member revokes their access and rotates the remaining key envelopes, so their old copy of the key stops opening anything new. Every membership change is written to an append-only audit trail.

What if we lose a password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to keep offline. That is the same property that stops anyone else, including us, from reading your workspace.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload