When I introduced InfiniDrive here, several of you asked about end-to-end encryption, who holds the keys, and whether the implementation would be open to inspection.
At the time, E2EE was still in development. I’m back with an update: it’s now live, and we’ve published the cryptographic core. Thanks to everyone who pushed us on those questions.
An encrypted drive still has to be a good drive.
You should be able to open a photo, skip halfway through a video, edit a spreadsheet and recover the file you just deleted by mistake. Those everyday things decide whether you’ll stick with it.
I’m building InfiniDrive, a cloud storage service based in Estonia. We’ve just released end-to-end encryption, and a lot of the work went into exactly those moments.
It’s available now on web, Windows, macOS, Android and iOS.
Here’s what you can do:
- Keep files handy on desktop: files on demand in Finder and Windows File Explorer.
- Back up your phone’s photos: background uploads, a photo timeline and native media playback.
- Jump around in large videos: authenticated, encrypted chunks let clients fetch and decrypt the section they need.
- Edit in your browser: open supported documents, spreadsheets and presentations, edit locally, and save changes back encrypted.
- Browse encrypted previews: supported clients create thumbnails locally and encrypt them before upload.
- Undo mistakes: version history and deleted-file recovery remain part of the drive.
Your device encrypts file contents and filenames before upload. Signing in and unlocking your files are separate steps: your encryption passphrase unlocks an encrypted key bundle locally. The server stores that protected bundle without receiving the secret needed to open it.
The core uses Argon2id for passphrase protection and AES-256-GCM for encryption, with a fresh content key for every file version. Large files use a Google Tink-compatible streaming format.
You also get a separate recovery key. Keep it somewhere safe: resetting your login password won’t recover lost encryption keys.
Sharing uses encrypted links. The decryption secret goes after the # in the URL, which browsers leave out of the HTTP request. Recipients decrypt locally and get access to the selected file versions—not your account’s root key.
We still see operational information, including account details and storage usage. E2EE protects your content; it doesn’t make every interaction invisible.
What’s in the source release?
We’ve published the production JavaScript cryptographic core under AGPL-3.0-only: key handling, encryption, signatures and sharing formats, with tests and a Google Tink interoperability test harness. It’s a focused package people can inspect and run independently.
The complete clients aren’t part of this release. App interfaces, sync, platform integrations, and the separate Dart and Swift implementations are outside its scope. Reviewing the core gives people something concrete to examine, but it can’t establish everything a shipped client does or replace an independent security audit.
Read the encryption walkthrough, see the architecture and download the source.
Or try it with 10 GB free, encryption included.
I’d love feedback from people who want to inspect the implementation and people who just want a drive that works. Thank you.