Client-side encryption
Contents, names and file structure are encrypted on the user’s device before the data leaves it.
Security & Zero-Knowledge
Nodrive encrypts data before it reaches the storage selected by the user and clearly states the limits of its Beta security model.
Contents, names and file structure are encrypted on the user’s device before the data leaves it.
The Beta keeps data locally or sends encrypted blocks to storage selected by the user. Fiscalbox does not offer Hosted storage for user content.
The User Key is unlocked locally with a password-derived key. In the current Beta, the wrapped User Key remains on the device and is not held in Nodrive cloud escrow.
The current technical model uses OPAQUE so the password is not sent to the server in plaintext. Backend communications use TLS.
With Google Drive, the user authorises access through OAuth. Nodrive does not receive the Google password and the authorisation token remains on the user’s PC.
A compromised device, weak password, malware, keyloggers or files created outside Nodrive can reduce the model’s protections. No claim guarantees absolute invulnerability.