Security

Privacy isn't a feature — it's the foundation

AES-256-GCM end-to-end encryption, 3-factor login, per-folder locks, inactivity auto-lock, full audit trail, encrypted backups. Your data, your keys.

Security

Privacy & Security First

Built from the ground up with privacy as the foundation — not an afterthought.

End-to-End Encryption

AES-256

All data is encrypted using AES-256-GCM before storage. Only you hold the keys — not even we can read your data.

Zero-Knowledge Architecture

0 Access

We never see, store, or process your unencrypted data. Your privacy is guaranteed by design, not by policy.

Multi-Layer Authentication

3 Factors

Three layers of security: password, TOTP authenticator, and device/IP verification protect your account at every step.

Brute-Force Protection

Auto-Lock

Intelligent rate limiting and automatic account lockout after failed attempts stop brute-force attacks before they start.

Full Audit Trail

100% Logged

Every login, password change, and security event is logged with timestamps and IP addresses for complete accountability.

Inactivity Auto-Lock

5 Min Lock

Sessions automatically lock after 5 minutes of inactivity. Leave your device unattended — your data stays protected.

Security Headers

6 Headers

HSTS, X-Frame-Options DENY, strict referrer policies, and permissions controls block clickjacking, XSS, and protocol downgrades.

Password Strength Enforcement

12+ Chars

Passwords must meet strict complexity requirements: 12+ characters with uppercase, lowercase, numbers, and symbols.

Encrypted Cloud Storage

Up to 20 TB

Up to 20 TB of cloud storage powered by Cloudflare's global network. Every file is AES-256 encrypted server-side before upload — unreadable even if storage is breached.

Role-Based Access (Teams)

4 Roles

Workspace members fall into Owner / Admin / Member / Viewer roles, each with surgical permissions on every resource. Owners can force 2FA and session timeouts org-wide.

Per-Workspace Audit Log

CSV + SIEM

Immutable, tamper-resistant log of every login, share, upload, delete, role change, AI message and admin action. Filterable in-app, CSV export anytime, SIEM streaming on Enterprise.

BYOK Encryption (Enterprise)

Your Keys

Bring your own AWS KMS, GCP KMS or HSM-backed key. Atomic key rotation, customer-controlled revocation. Our engineers cannot decrypt your data — by design.

Your Data Deserves Fortress-Level Protection

AES-256 encryption, 3-factor authentication, zero-knowledge architecture, and per-module security gates — for one person or a whole team. Stop trusting platforms that read your data — own it.