Finance

Client and deal documents that your cloud provider cannot open.

Wealth managers, funds and fintechs handle material that is valuable to attackers and regulated by everyone. Removing the provider's key removes an entire category of exposure.

Market-sensitive material, readable only by the people on the deal.

For advisory firms, asset managers, funds, corporate finance teams and fintech companies exchanging confidential client and transaction documents.

Built for confidentiality

Deal and client rooms

Encrypted spaces per client or transaction, with keys sealed per participant and rotation on removal.

Watermarked distribution

Send a memorandum or model with a per-recipient watermark and a view budget.

Defensible logging

An append-only record of access and sharing that you can export for internal audit, without content exposure.

Encrypted internal channels

Discuss a live transaction without that discussion living in a vendor-readable chat history.

Credential hygiene

A built-in encrypted secrets vault so portal logins stop circulating in spreadsheets and chats.

Strong authentication

Passkeys, TOTP and reviewable sessions, with step-up verification for sensitive actions.

Insider risk and market-sensitive information

Access control is not only about outsiders. Per-participant key envelopes mean a colleague outside the deal has no cryptographic path to the documents, regardless of what an administrator clicks. Removing someone rotates keys and leaves an entry in the record.

Client onboarding without loose attachments

KYC packs contain exactly the identity documents attackers want. Collecting them through a protected link into an encrypted drive, rather than as email attachments, means no readable copy sits in a mailbox for years.

Compliance posture, stated plainly

We do not hold SOC 2 or ISO 27001 today and we publish that. For firms whose policy requires certification, the honest answer is that we are not yet on your approved list; for firms assessing actual technical exposure, client-side encryption is a stronger control than most certified stacks provide.

Frequently asked questions

Can we export an access log for an audit?

+

Yes. The audit trail is append-only and exportable, and it records access and sharing events without recording document contents.

How do you handle large models and datasets?

+

Uploads are chunked, resumable and verified after upload by sampling authenticated chunks, so large files transfer reliably.

Can DRIVUNO read our documents or messages?

+

No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need an IT team to deploy it?

+

No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.

What certifications do you hold today?

+

We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.

What happens if someone leaves the firm?

+

Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.

What if a user loses their password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.

Is there a free plan to evaluate it?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload