Store and share files without handing the keys to the infrastructure
SecureRepository combines a modern drive experience with client-side encryption, protected metadata, enterprise identity management and structured auditing. The server stores encrypted content, relationships and permissions; plaintext data exists in authorised clients during ordinary use.
- Client-side encryption for content, filenames and folders
- Internal and external sharing with separate keys
- SSO, SCIM, MFA, passkeys and enterprise roles
Encryption as the trust boundary
Encryption is not an additional storage layer: it determines which components can access data and how keys are distributed.
Encryption before storage
Files and sensitive metadata are encrypted in the client before persistence. Storage uses opaque identifiers and does not place document names in object paths.
Independent keys for files and folders
Each file has a dedicated random key. The key hierarchy supports selective sharing, rotation and recovery without exposing a universal server-side decryption key.
Established cryptographic primitives
The design uses XChaCha20-Poly1305, X25519, Ed25519, Argon2id and HKDF-SHA-256 through a versioned Rust and WebAssembly cryptographic component, without proprietary algorithms.
Client-side search and previews
The browser decrypts authorised metadata and builds the search index locally. Previews are also generated in the client and stored as encrypted objects.
File management without sacrificing confidentiality
The web interface concentrates the functions required to store, organise, recover and share documents without becoming a general-purpose collaboration suite.
Large files
Streaming encryption, parallel multipart uploads, resumption, per-chunk retries and cancellation avoid loading an entire file into memory. The architecture is designed for files of at least 100 GiB; the effective limit depends on configuration and must be validated.
Versions, trash and recovery
Each update creates a separate revision that can be reviewed and restored. Deletion initially moves items to the trash; retention periods and permanent deletion are configurable by organisation.
Operational interface
List and grid views, multi-selection, keyboard navigation, drag and drop, context menus and breadcrumbs cover daily operations. Available actions follow user permissions.
Cryptographic internal and external sharing
Granting access distributes the required keys without making the server the holder of plaintext file keys.
Internal collaborators
Files and folders can be shared with Viewer, Editor and Manager roles. Keys are wrapped separately for each recipient, so access can be granted and revoked without distributing master keys.
External recipients
Encrypted links can include a password, expiry, revocation, download limits and download disabling. The decryption secret can remain in the URL fragment, which is not transmitted to the server in an ordinary HTTP request.
Enterprise identity, access and governance
Enterprise capabilities integrate with client-side encryption without introducing general access to content.
SSO and identity lifecycle
OIDC, SAML 2.0, Microsoft Entra ID, Okta, Keycloak and Google Workspace cover federation; SCIM 2.0 manages provisioning, deactivation and group synchronisation.
Authentication and sessions
WebAuthn passkeys, TOTP, recovery codes and MFA policies are combined with session inventory, selective revocation and global logout.
Isolation and roles
Tenants, organisations and capability-based permissions separate customers and centralise access decisions. Roles distinguish ownership, administration, security, audit, members and guests.
Explicit and verifiable recovery
Account recovery remains separate from key recovery. Organisations can enable an enterprise recovery public key; this choice changes the confidentiality model and every use is recorded.
Tamper-evident enterprise auditing
Authentication, files, shares, roles, policies and recovery operations generate structured, searchable and exportable events.
Contextualised events
Each event associates, where relevant, tenant, actor, session, action, resource, outcome, IP address, request ID and trace ID. Server-side filters support investigations across high event volumes.
Detectable alteration
Records are appended and batches are cryptographically chained. A WORM archive or S3 Object Lock can add non-rewritable retention; the hash chain makes changes to history detectable.
Export and integration
JSONL, CSV, syslog, SIEM, webhooks and event streams connect auditing to the organisation’s existing monitoring and retention processes.
Deployment options
The scope is defined around document volumes, the enterprise systems to integrate and the required level of operational autonomy.
Dedicated deployment
SecureRepository can be deployed in an environment dedicated to the organisation, with configuration and capacity sized around the agreed scope.
Enterprise infrastructure
The deployment can use infrastructure services already managed by the organisation, keeping data segregated and integrating with existing operating policies.
Storage under your control
Encrypted content can be held in storage selected by the organisation. Infrastructure encryption adds another layer of protection and does not replace client-side encryption.
Integration with existing processes
Identity, automation, auditing and monitoring can connect to existing tools through standard interfaces and credentials with limited permissions.
Limits and responsibilities
The encryption model reduces infrastructure access to data, but requires explicit decisions about keys, recovery and operations.
No implicit key recovery
Resetting a password does not recreate unavailable encryption keys. Personal or enterprise recovery material must be configured, protected and tested in advance.
Residual operational metadata
Content and sensitive metadata are encrypted, but the service must process relationships, permissions, sizes, timing and technical data required for operation and security.
Enterprise recovery as a trust decision
Enabling enterprise recovery allows authorised parties to recover keys covered by policy. This capability must be disclosed to users and governed through roles and auditing.
Compliance support, not certification
Audit, MFA, access controls, retention, backups and monitoring can produce evidence for GDPR, NIS 2, DORA, ISO 27001 and SOC 2 programmes. The platform does not automatically make an organisation compliant or certified.
File repository assessment
DEC can review volumes, identities, recovery policies, storage, audit requirements and deployment options to define a verifiable SecureRepository scope.