Transparency

Infrastructure & Providers

A truthful, current map of where DRIVUNO runs. Every provider listed here sees encrypted blobs or operational metadata only — never your plaintext content or keys.

How to read this page

Because content is encrypted before it leaves your device, providers in the data path cannot read it. We still list them, because supply-chain transparency matters even when the cryptography neutralizes them. DRIVUNO is EU-first: primary regions for the database and object storage default to the EU for every account, and server-side logic runs on an edge runtime that only ever handles ciphertext and signed requests.

For the full, current list of named vendors and what each one processes, see the subprocessor register. This page intentionally stays at the level of architecture, not specific hostnames or storage bucket names.

Today's stack

Edge runtime
Globally distributed edge compute runs server-side rendering, the API, and webhook delivery. Sees signed requests and ciphertext, never plaintext content or keys.
Database — managed Postgres
Stores account records, sealed key envelopes, ciphertext references, and audit logs. Row-Level Security on every sensitive table. Primary region: EU.
Object storage
Holds encrypted file blobs for the Vault, Rooms attachments, and Live Clone. Provider-side encryption-at-rest is enabled as defense in depth, on top of client-side encryption.
Email & SMS delivery
Transactional email and optional SMS for verifications, recovery, and notifications. Sees the address/number and the message we generate; never user files.
Payments
Card / SEPA / wallet processing plus regional fallbacks for sovereignty. Sees billing data only, never linked to file activity.
Multi-provider failover
Continuous monitoring across providers with automatic failover, backed by a public status page. See the sovereignty page.

What each provider can see

  • Compute / edge: request URLs, request bodies (ciphertext for file, Rooms, and API operations), authentication headers.
  • Database: account records, sealed envelopes, ciphertext references, audit logs. No keys, no plaintext.
  • Object storage: encrypted blobs and their sizes, for the Vault, Rooms attachments, and Live Clone. Nothing else.
  • Backup tier: the same encrypted snapshots as production, held immutable in the EU off-site backup tier.
  • Email / SMS: the addresses or phone numbers we send to, plus the message body we generate (never user files).
  • Payments: name, billing address, card metadata. Never linked to file activity.

Region strategy

EU-first
Database, object storage, and the off-site backup tier default to the EU for every new account.
Continuous monitoring & failover
Providers are monitored continuously; automatic failover switches traffic within minutes, and status is tracked publicly on our status page.
Japan + APAC (planned)
Regional residency for APAC accounts is on the roadmap. Tracked publicly on the security roadmap.

Becoming provider-agnostic

Our storage layer uses a thin adapter pattern over S3-compatible object storage. Migrating between providers does not change the cryptography or expose user content, because providers only ever held ciphertext.

See also: subprocessors list, metadata policy, sovereignty & resilience.

Encrypted on your device · upload in 1 click
Upload