Contact DEC
Language:ITEN
End‑to‑end encrypted file repository

Store and share files without handing the keys to the infrastructure

SecureRepository combines a modern drive experience with client-side encryption, protected metadata, enterprise identity management and structured auditing. The server stores encrypted content, relationships and permissions; plaintext data exists in authorised clients during ordinary use.

  • Client-side encryption for content, filenames and folders
  • Internal and external sharing with separate keys
  • SSO, SCIM, MFA, passkeys and enterprise roles

Encryption as the trust boundary

Encryption is not an additional storage layer: it determines which components can access data and how keys are distributed.

Encryption before storage

Files and sensitive metadata are encrypted in the client before persistence. Storage uses opaque identifiers and does not place document names in object paths.

Independent keys for files and folders

Each file has a dedicated random key. The key hierarchy supports selective sharing, rotation and recovery without exposing a universal server-side decryption key.

Established cryptographic primitives

The design uses XChaCha20-Poly1305, X25519, Ed25519, Argon2id and HKDF-SHA-256 through a versioned Rust and WebAssembly cryptographic component, without proprietary algorithms.

Client-side search and previews

The browser decrypts authorised metadata and builds the search index locally. Previews are also generated in the client and stored as encrypted objects.

File management without sacrificing confidentiality

The web interface concentrates the functions required to store, organise, recover and share documents without becoming a general-purpose collaboration suite.

Large files

Streaming encryption, parallel multipart uploads, resumption, per-chunk retries and cancellation avoid loading an entire file into memory. The architecture is designed for files of at least 100 GiB; the effective limit depends on configuration and must be validated.

Versions, trash and recovery

Each update creates a separate revision that can be reviewed and restored. Deletion initially moves items to the trash; retention periods and permanent deletion are configurable by organisation.

Operational interface

List and grid views, multi-selection, keyboard navigation, drag and drop, context menus and breadcrumbs cover daily operations. Available actions follow user permissions.

Cryptographic internal and external sharing

Granting access distributes the required keys without making the server the holder of plaintext file keys.

Internal collaborators

Files and folders can be shared with Viewer, Editor and Manager roles. Keys are wrapped separately for each recipient, so access can be granted and revoked without distributing master keys.

External recipients

Encrypted links can include a password, expiry, revocation, download limits and download disabling. The decryption secret can remain in the URL fragment, which is not transmitted to the server in an ordinary HTTP request.

Enterprise identity, access and governance

Enterprise capabilities integrate with client-side encryption without introducing general access to content.

SSO and identity lifecycle

OIDC, SAML 2.0, Microsoft Entra ID, Okta, Keycloak and Google Workspace cover federation; SCIM 2.0 manages provisioning, deactivation and group synchronisation.

Authentication and sessions

WebAuthn passkeys, TOTP, recovery codes and MFA policies are combined with session inventory, selective revocation and global logout.

Isolation and roles

Tenants, organisations and capability-based permissions separate customers and centralise access decisions. Roles distinguish ownership, administration, security, audit, members and guests.

Explicit and verifiable recovery

Account recovery remains separate from key recovery. Organisations can enable an enterprise recovery public key; this choice changes the confidentiality model and every use is recorded.

Tamper-evident enterprise auditing

Authentication, files, shares, roles, policies and recovery operations generate structured, searchable and exportable events.

Contextualised events

Each event associates, where relevant, tenant, actor, session, action, resource, outcome, IP address, request ID and trace ID. Server-side filters support investigations across high event volumes.

Detectable alteration

Records are appended and batches are cryptographically chained. A WORM archive or S3 Object Lock can add non-rewritable retention; the hash chain makes changes to history detectable.

Export and integration

JSONL, CSV, syslog, SIEM, webhooks and event streams connect auditing to the organisation’s existing monitoring and retention processes.

Deployment options

The scope is defined around document volumes, the enterprise systems to integrate and the required level of operational autonomy.

Dedicated deployment

SecureRepository can be deployed in an environment dedicated to the organisation, with configuration and capacity sized around the agreed scope.

Enterprise infrastructure

The deployment can use infrastructure services already managed by the organisation, keeping data segregated and integrating with existing operating policies.

Storage under your control

Encrypted content can be held in storage selected by the organisation. Infrastructure encryption adds another layer of protection and does not replace client-side encryption.

Integration with existing processes

Identity, automation, auditing and monitoring can connect to existing tools through standard interfaces and credentials with limited permissions.

Limits and responsibilities

The encryption model reduces infrastructure access to data, but requires explicit decisions about keys, recovery and operations.

No implicit key recovery

Resetting a password does not recreate unavailable encryption keys. Personal or enterprise recovery material must be configured, protected and tested in advance.

Residual operational metadata

Content and sensitive metadata are encrypted, but the service must process relationships, permissions, sizes, timing and technical data required for operation and security.

Enterprise recovery as a trust decision

Enabling enterprise recovery allows authorised parties to recover keys covered by policy. This capability must be disclosed to users and governed through roles and auditing.

Compliance support, not certification

Audit, MFA, access controls, retention, backups and monitoring can produce evidence for GDPR, NIS 2, DORA, ISO 27001 and SOC 2 programmes. The platform does not automatically make an organisation compliant or certified.

File repository assessment

DEC can review volumes, identities, recovery policies, storage, audit requirements and deployment options to define a verifiable SecureRepository scope.