Security file · Helvedrive

Client-side encryption and key control for businesses

For trade secrets, a storage location is not enough. The planned architecture encrypts documents on authorised devices, with keys under your organisation’s control.

The plans describe the premium offering currently in development. The quote sets out integrations, timelines and commitments; real data is accepted after the security and restore validations.

Three questions before entrusting a document

Who can read the content? Who holds the necessary keys? Who can modify the software used for decryption? The security file must answer these three questions for normal operation and for compromise scenarios.

The vault and the Drive serve different purposes

The Drive enables collaboration and authorised server-side processing. The vault aims to keep content confidential from the service and the hosting provider. Full-text search, AI and server-side antivirus scanning cannot read this content without changing this model.

Recovering an account must not open the vault

A passkey is used to authenticate a user. It is not, in itself, the key to their documents. Administrators, authorised devices and key recovery must follow a separate procedure. Losing all keys and their means of recovery can make documents unrecoverable.

Legal requests and devices remain part of the model

The service remains subject to applicable law. Encryption aims to limit access to stored content; it does not guarantee anonymity, the erasure of all metadata or the security of a compromised device. The delivery and updates of the client software must also be controlled.

Scoping in confidence

Let’s define the scope of your protection.

Team, sensitive data, keys, location and recovery: let’s discuss your requirements. Please do not send any confidential documents through the form.