Legal

Secure file sharing for law firms, where the provider holds no key.

Client documents, discovery bundles and deal files leave your machine already encrypted. Our servers store ciphertext, so confidentiality does not depend on our staff, our vendors or our good behaviour.

Confidentiality you can describe to a client in one sentence: nobody outside the matter can read it.

For boutique firms, in-house legal teams, litigation and transactional practices exchanging privileged material with clients, co-counsel and experts.

Built for confidentiality

Encrypted before upload

Documents are sealed on the device. What reaches our infrastructure is ciphertext plus a sealed key envelope for each authorised person.

One link per recipient

Protected links with passphrase, expiry, view budget and revocation — so a forwarded link is traceable and can be cut off.

Watermarked viewing

Sensitive documents can be viewed with a per-recipient watermark, which discourages screenshots and identifies the source.

Append-only audit trail

Access, membership changes, share creation and revocation are logged without exposing document content.

Matter-scoped spaces

Each matter gets its own encrypted drive and channel, with keys sealed per member — not one shared folder for the whole firm.

Retention you control

A 30-day trash, versioning and explicit deletion, so files disappear when the engagement ends rather than lingering indefinitely.

Why generic cloud storage is awkward for privileged material

Mainstream storage products encrypt in transit and at rest, but they keep the keys: that is what enables server-side previews, indexing and administrative recovery. It also means readable copies of privileged documents exist on infrastructure your client never chose. Zero-knowledge removes that class of exposure — not by policy, but because the plaintext never exists outside your devices.

Client exchange without email attachments

Most privilege incidents are mundane: a wrong autocomplete, a huge attachment bounced and re-sent via a consumer transfer service, a link shared with an assistant who forwards it. Per-recipient protected links replace those habits with something you can revoke, expire and log — while remaining as simple for the client as clicking a URL and typing a passphrase.

Co-counsel, experts and opposing parties

External participants do not need an account to receive documents, and internal participants get matter-scoped access instead of blanket firm-wide access. When an expert's engagement ends, removing them rotates the remaining keys for that matter, so their stored copy of a key opens nothing new.

What we do not claim

We do not hold SOC 2 or ISO 27001 certification today and we do not pretend that any tool makes a firm compliant on its own. What a zero-knowledge architecture gives you is a defensible technical answer to the question a client, regulator or insurer will ask: who can read this, and how do you know?

Frequently asked questions

Is zero-knowledge storage suitable for privileged client documents?

+

It is the closest technical match to the duty of confidentiality: the provider has no ability to read the material, so the set of people who can read it is exactly the set you granted. You should still apply your jurisdiction's rules on client consent and cloud use.

Can we prove who accessed a document?

+

Yes. Access events, link creation, link use and membership changes are recorded in an append-only trail you can export, without recording document contents.

Can clients receive files without creating an account?

+

Yes. A protected link carries the decryption material in the URL fragment, which is never sent to our servers, and is additionally locked behind a passphrase you communicate separately.

How large can discovery bundles be?

+

Uploads are chunked, resumable and verified, so multi-gigabyte bundles survive a dropped connection or a closed laptop without restarting from zero.

Can DRIVUNO read our documents or messages?

+

No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need an IT team to deploy it?

+

No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.

What certifications do you hold today?

+

We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.

What happens if someone leaves the firm?

+

Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.

What if a user loses their password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.

Is there a free plan to evaluate it?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload