Private by architecture, not by policy

Store what matters. Keep it private.

Family photos. Tax documents. The backups you'd never want a stranger — or a company — flipping through. Drive encrypts everything on your device before it's uploaded, so what reaches us is unreadable without your key. We still store the encrypted bytes; we just can't make sense of them. That's not a promise we're making. It's how the system is built.

One platform, more products coming

Drive is live today. Everything else on this page shares the same anhe.io account, the same key, the same guarantee — as it ships.

Live

Drive

Encrypted file storage. Available now.

Coming soon

Notes

An encrypted notes app, on the same account.

Coming soon

Obsidian Sync

Sync an Obsidian vault with your anhe.io storage.

Coming soon

Mail

Encrypted email, same key hierarchy as Drive.

How it works

Three steps, all of them on your device before anything reaches us.

Encrypted on your device

Every Drive client shares one Rust cryptography core. It derives keys from your passphrase and encrypts your files — and their names — locally. Your passphrase never leaves your device.

Only ciphertext reaches us

Encrypted chunks go straight to object storage over short-lived presigned URLs; file bytes never pass through our API. It handles authorisation and custody of wrapped keys — never plaintext.

You hold the only keys

Unlocking your account unwraps your master key on your device, from your passphrase. There is no server-side copy and no operator-side recovery.

Built for what comes after Drive

One crypto core, one identity model, one storage layer — designed to carry the same guarantee across Photos, Docs, and Mail as the suite grows, not bolted on product by product.

Google Drive / Dropbox"Encrypted" storage, typicallyDrive
Server can read your filesYesSometimes — often at rest onlyNever
Who holds the keysThe providerProvider, via a recovery flow that quietly reintroduces oneYou, always
Content used for ads / trainingYes, commonlyVaries, undisclosedCan't — no plaintext to use
Crypto implementationClosedClosed, unauditableOne open, auditable Rust core

What we can see — and what we can't

We publish exactly what the service has access to, including the parts that are not flattering: the browser is the weakest way to use Drive, file sizes and timestamps stay visible, and our identity provider sees signup emails and IP addresses.

Read the security page before you trust us →

Your files. Your keys. Not ours to lose.

Start with the web app, move to desktop when it ships — the same crypto core, the same account, either way.