Why 'remember me' is usually a downgrade
Classic session cookies mean a stolen token equals a stolen account. A trusted device here holds a key the browser refuses to export, bound to that origin and that machine.
Trust a device once and unlock with Face ID or a PIN, while the key material stays non-extractable in secure browser storage.
“Convenience that adds hardware, not exceptions.”
For daily users of an encrypted workspace who need it to open in a second on phone and desktop without lowering the bar for an attacker.
Face ID, Touch ID or Windows Hello release a device-bound wrapping key; your master key is never stored in a readable form.
A trusted device holds a non-extractable WebCrypto key in IndexedDB. It cannot be copied out, and it is destroyed on sign-out or revocation.
WebAuthn passkeys plus TOTP MFA, with step-up authentication before sensitive operations.
A session from an unfamiliar country is logged as a warning in your immutable audit trail.
Revoke a session or a device from the Security Center and its sealed key copies stop working immediately.
A printable PDF with QR code that restores access offline — the only recovery path, because we hold no copy of your key.
Classic session cookies mean a stolen token equals a stolen account. A trusted device here holds a key the browser refuses to export, bound to that origin and that machine.
Every shortcut sits on top of the same client-side key derivation. None of them create a server-side path to your plaintext, and none of them let support open an account.
Devices, sessions, recovery-key age and MFA status are listed in the Security Center, with an append-only audit log you can review at any time.
No. Passwords, emails, documents and search indexes are encrypted on your device with XChaCha20-Poly1305. Keys are derived locally from your password with Argon2id and wrapped per member with X25519. Servers store ciphertext only.
DRIVUNO uses blind indexes: your device computes HMAC tags for names, subjects and fields, and the server matches tags without ever seeing plaintext. Results are decrypted in your browser.
Yes. The free plan includes 1 GB with the same zero-knowledge architecture — encrypted drive, Rooms, mail, secrets, docs and search.
Because we cannot read your data, we cannot reset it. Create a Recovery Kit (printable PDF with QR) and store it offline. Without your password or recovery key, encrypted data cannot be recovered — by design.
No. DRIVUNO has no advertising business, performs no content analysis, and cannot train models on data it is unable to decrypt.
Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.