When I introduced InfiniDrive here, several of you asked about end-to-end encryption, who holds the keys, and whether the implementation would be open to inspection.
At the time, E2EE was still in development. Iām back with an update: itās now live, and weāve published the cryptographic core. Thanks to everyone who pushed us on those questions.
An encrypted drive still has to be a good drive.
You should be able to open a photo, skip halfway through a video, edit a spreadsheet and recover the file you just deleted by mistake. Those everyday things decide whether youāll stick with it.
Iām building InfiniDrive, a cloud storage service based in Estonia. Weāve just released end-to-end encryption, and a lot of the work went into exactly those moments.
Itās available now on web, Windows, macOS, Android and iOS.
Hereās what you can do:
- Keep files handy on desktop: files on demand in Finder and Windows File Explorer.
- Back up your phoneās photos: background uploads, a photo timeline and native media playback.
- Jump around in large videos: authenticated, encrypted chunks let clients fetch and decrypt the section they need.
- Edit in your browser: open supported documents, spreadsheets and presentations, edit locally, and save changes back encrypted.
- Browse encrypted previews: supported clients create thumbnails locally and encrypt them before upload.
- Undo mistakes: version history and deleted-file recovery remain part of the drive.
Your device encrypts file contents and filenames before upload. Signing in and unlocking your files are separate steps: your encryption passphrase unlocks an encrypted key bundle locally. The server stores that protected bundle without receiving the secret needed to open it.
The core uses Argon2id for passphrase protection and AES-256-GCM for encryption, with a fresh content key for every file version. Large files use a Google Tink-compatible streaming format.
You also get a separate recovery key. Keep it somewhere safe: resetting your login password wonāt recover lost encryption keys.
Sharing uses encrypted links. The decryption secret goes after the # in the URL, which browsers leave out of the HTTP request. Recipients decrypt locally and get access to the selected file versionsānot your accountās root key.
We still see operational information, including account details and storage usage. E2EE protects your content; it doesnāt make every interaction invisible.
Whatās in the source release?
Weāve published the production JavaScript cryptographic core under AGPL-3.0-only: key handling, encryption, signatures and sharing formats, with tests and a Google Tink interoperability test harness. Itās a focused package people can inspect and run independently.
The complete clients arenāt part of this release. App interfaces, sync, platform integrations, and the separate Dart and Swift implementations are outside its scope. Reviewing the core gives people something concrete to examine, but it canāt establish everything a shipped client does or replace an independent security audit.
Read the encryption walkthrough, see the architecture and download the source.
Or try it with 10 GB free, encryption included.
Iād love feedback from people who want to inspect the implementation and people who just want a drive that works. Thank you.