A virtual data room the provider cannot read, without per-page pricing.
Diligence needs controlled distribution, watermarking, expiry and an access record. It does not need a vendor with a decryption key and a metered invoice.
“All the control of a data room, none of the readable copies.”
For corporate lawyers, founders, investors and advisers running diligence, fundraising or transaction workstreams.
Built for confidentiality
Structured encrypted rooms
Organise the disclosure set into folders whose names and contents are both encrypted.
Per-viewer watermarking
Each viewer sees their own watermark, so a leaked screenshot points to a specific recipient.
Expiry and view budgets
Links expire on a deadline and can be limited to a number of views, then revoked in one click.
Access record
Who opened what and when, exportable, without the provider seeing the documents.
Q&A in the same place
Encrypted channels keep diligence questions with the documents instead of in a separate readable chat tool.
Predictable pricing
Storage-based plans rather than per-page or per-user data-room metering.
Where classic data rooms are strong — and where they are not
Data rooms are good at controlled distribution, indexes and reporting. They are conventional server-side systems: the operator can render, index and therefore read every document. For most transactions that is accepted; for sensitive IP, source code, patient or client material it deserves a second look.
What changes with zero-knowledge
The controls stay — watermark, expiry, revocation, logs — but the operator's copy is ciphertext. Distribution is enforced by keys and link fragments rather than by a rendering server that holds plaintext.
After the deal closes
Revoke every external link, remove external members to rotate keys, export the audit trail for the file, and delete the room. Nothing survives on someone else's index.
Frequently asked questions
Can we prevent downloads entirely?
+
You can restrict a link to watermarked viewing rather than download. As with every system, a determined viewer can photograph a screen — which is exactly why per-viewer watermarking matters.
Do bidders need accounts?
+
No. Protected links work without an account, with a passphrase shared through a separate channel.
Can DRIVUNO read our documents or messages?
+
No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.
Do we need an IT team to deploy it?
+
No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.
What certifications do you hold today?
+
We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.
What happens if someone leaves the firm?
+
Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.
What if a user loses their password?
+
Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.
Is there a free plan to evaluate it?
+
Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.