Google Drive alternative

A drive that receives your files as ciphertext.

Encryption happens in your browser or app before the upload starts. We store bytes we have no key for.

If we are breached, compelled or mistaken, your files stay unreadable.

For firms and teams storing client files, contracts, patient or financial data, source code and unreleased work in the cloud.

Built for confidentiality

Encrypted before upload

XChaCha20-Poly1305 payloads under keys derived on the device with Argon2id. No key ever reaches us in usable form.

Team folders with per-member keys

Each Team Drive folder key is sealed individually to every member with X25519 and rotated when someone is removed.

Large uploads that survive reality

Chunked, resumable after a crash or a dropped connection, and verified afterwards by sampling authenticated segments.

Search on blind indexes

Names and tags are matched through HMAC indexes computed on your device — the server never sees plaintext.

Links with a hard fuse

Passphrase-gated public links, key material in the URL fragment only, expiring within 24 hours at most.

Independent encrypted backups

Hourly encrypted snapshots to independent immutable storage, with restore that has actually been tested.

What Google Drive can do that we deliberately cannot

Google Drive is operationally excellent and reads your content in order to be so: full-text search across documents, universal previews, thumbnails, scanning, real-time co-editing and assistant features all require plaintext on the server. We cannot offer those, because we cannot read your files. That is the trade, stated plainly.

Sorting your data before you migrate

Move confidential material first: client work, contracts, personal data, source code, unreleased product. Leave public and disposable material where it is convenient. Most teams find the confidential subset is smaller than expected and easy to isolate — and mixing the two is what makes privacy projects stall.

Recovery is your responsibility, and we make it survivable

There is no password reset that restores data, because that would require a key on our side. Instead, every member generates a recovery kit to store offline, shared work lives in team folders keyed to more than one person, and encrypted snapshots to independent storage mean a provider incident never becomes a data-loss event.

Frequently asked questions

Can DRIVUNO read our messages or files?

+

No. Content is encrypted on your device before upload. Account keys are derived locally with Argon2id, room and folder keys are wrapped per member with X25519, and payloads are sealed with XChaCha20-Poly1305. Our servers store ciphertext and wrapped keys.

How is that different from 'encrypted in transit and at rest'?

+

Transit and at-rest encryption use keys held by the provider, which is why server-side search, previews, scanning and administrative export are possible. Client-side encryption removes the provider from the set of parties able to read content.

What do we lose by moving to zero-knowledge?

+

Provider-side full-text search over document contents, universal server-generated previews, content AI on your data, administrative content export, and password resets that recover data. Search runs on device-side blind indexes and recovery relies on a recovery kit you keep offline.

What happens when someone leaves?

+

Removal revokes their sealed copy of the room or folder key and triggers rotation, so future content is sealed under a key they never held.

How does external sharing work?

+

Public links carry key material in the URL fragment, which browsers never transmit to a server, are gated by a passphrase and expire within 24 hours at most. Links can be revoked earlier and view counts capped.

Do we have to migrate everything at once?

+

No, and most teams should not. Move the confidential surface first — client work, matters, deals, personal data, unreleased product — and keep general coordination where it is until the pilot proves out.

Related

Your sensitive files deserve more than a traditional cloud.

Start free with 1 GB. Zero-knowledge encryption from the first upload — no admin override, no AI scanning, no plaintext on the server.

1 GBfree vault
Encrypted on your device · upload in 1 click
Upload