Platform

A collaboration platform with no readable copy on the server.

Zero-knowledge is usually a feature of one product. Here it is the property of the whole workspace: messages, files, documents, mail, calls and secrets.

One workspace, one key hierarchy, nothing legible on our side.

For teams evaluating encrypted collaboration platforms and comparing them against self-hosted or federated alternatives.

Built for confidentiality

Whole-workspace encryption

Not just chat or just storage: documents, tasks, mail, photos, credentials and calls all use the same client-side key hierarchy.

Per-member key envelopes

Group access is granted by sealing a key to each member with X25519, and revoked by rotation.

Private search across everything

Blind indexes computed on your device support searching messages, files and mail without a server-side content index.

No self-hosting

Hosted product, with the operator holding no key. You get SaaS operations without SaaS access.

Verifiable operations

Published subprocessors, storage regions, a transparency page and an append-only audit trail.

Offline-capable clients

Encrypted local caches on desktop and mobile so the workspace works on a plane or a bad hotel network.

How to evaluate any platform claiming zero-knowledge

Three questions separate architecture from marketing: can an administrator read a private channel or drive; exactly what does the server hold when a message or file is created; and what happens cryptographically when a member is removed. Vague answers to any of the three mean the provider retains a key somewhere.

Hosted versus self-hosted encrypted stacks

Self-hosted stacks give you control and give you an operational burden: upgrades, key management, backups, availability. Most teams that adopt them end up running them badly. A hosted zero-knowledge platform aims to remove the burden without granting the operator readable access.

The honest trade-offs

No provider-side content search, no integrations that require reading your data, no administrator password reset, and recovery that depends on an offline Recovery Kit. These are consequences of the guarantee, not gaps in the product.

Frequently asked questions

How is this different from federated or self-hosted options?

+

Those give you infrastructure control and require you to operate the infrastructure. This gives you a hosted service whose operator cannot read your data, with per-member key envelopes and rotation handled for you.

Do encrypted calls work like normal calls?

+

Yes: voice, video and screen share, with media encrypted end-to-end between participants and no server-side recording surface.

Can DRIVUNO read our documents or messages?

+

No. Everything is encrypted on the device before it is uploaded, with XChaCha20-Poly1305, using keys derived locally with Argon2id and wrapped per member with X25519. Our servers hold ciphertext and sealed key envelopes, so there is no admin view, no support tool and no classifier that can reach your content.

Do we need an IT team to deploy it?

+

No. There is nothing to self-host and no key server to operate. You create an account, invite colleagues and clients by email, and the encryption happens transparently in the browser, desktop and mobile apps.

What certifications do you hold today?

+

We do not currently hold SOC 2 or ISO 27001 certification, and we say so publicly rather than implying otherwise. Our compliance page documents where we are, what is in progress, and what is planned. What we can demonstrate today is the architecture itself: client-side encryption, per-member key envelopes and an append-only audit trail.

What happens if someone leaves the firm?

+

Removing a member revokes access and rotates the remaining key envelopes, so an old copy of a key stops opening anything new. Every membership change, share creation and revocation is written to an append-only log.

What if a user loses their password?

+

Because we cannot read your data, we cannot reset it for you. Each account creates a Recovery Kit — a printable PDF with a QR code — to be stored offline. That is the same property that stops anyone else, including us, from reading the account.

Is there a free plan to evaluate it?

+

Yes. The free plan includes 1 GB with exactly the same zero-knowledge architecture as paid plans, so you can validate a real client workflow before committing.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload