Communication

Internal communication that stays internal, cryptographically.

Your chat history contains strategy, salaries, incidents, customers and roadmaps. It should not be readable by a vendor, an integration or anyone who obtains a workspace export.

A workspace export from our side is a pile of ciphertext.

For companies replacing a mainstream chat product because message history is too sensitive to leave readable.

Built for confidentiality

Channels, DMs, threads

Everything a team expects — reactions, mentions, tasks, pinned items — with each message sealed for its exact recipients.

Encrypted calls and screen share

Voice, video and screen sharing between participants, without a provider-side media recording surface.

Attachments in the same vault

Files shared in a conversation live in your encrypted drive rather than in a second readable product.

Notifications without content

Push notifications carry no readable message content; the device decrypts locally.

Clean offboarding

Removing someone revokes access and rotates keys, and their historical access is recorded in the audit trail.

Migration from existing tools

Import exports from common chat products so history is not lost when you move.

Why chat history is the highest-value target in a company

Documents are edited and archived; chat is candid, continuous and complete. It contains the reasoning behind decisions, the incidents, the negotiations and the personnel discussions. If a single vendor account compromise can produce that history in plaintext, it is a strategic risk, not an IT detail.

Integrations, bots and the readable-by-default problem

Every bot added to a mainstream workspace typically receives broad read access to conversations. In an end-to-end encrypted workspace, that model does not exist: there is no server-side plaintext for an integration to consume, which removes convenience and removes the risk with it.

Adoption matters more than features

If the encrypted tool is slower, people route around it, and routing around it is the leak. Instant channel switching, cached transcripts, offline access and a familiar interface are security features in practice.

Frequently asked questions

Can we retain and export history for compliance?

+

Members can export the conversations they hold keys for. We cannot produce plaintext centrally, which is exactly the guarantee — so if your policy requires provider-side retention of readable messages, this architecture is not compatible with it.

Does search work across message history?

+

Yes, using blind indexes computed on your device, so the server matches opaque tags and your browser decrypts the results.

Can DRIVUNO read our documents or messages?

+

No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need an IT team to deploy it?

+

No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.

What certifications do you hold today?

+

We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.

What happens if someone leaves the firm?

+

Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.

What if a user loses their password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.

Is there a free plan to evaluate it?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload