Store what matters. Keep it private.
Family photos. Tax documents. The backups you'd never want a stranger — or a company — flipping through. Drive encrypts everything on your device before it's uploaded, so what reaches us is unreadable without your key. We still store the encrypted bytes; we just can't make sense of them. That's not a promise we're making. It's how the system is built.
- Rust crypto core
- Per-file keys
- No password reset
One platform, more products coming
Drive is live today. Everything else on this page shares the same anhe.io account, the same key, the same guarantee — as it ships.
Drive
Encrypted file storage. Available now.
Notes
An encrypted notes app, on the same account.
Obsidian Sync
Sync an Obsidian vault with your anhe.io storage.
Encrypted email, same key hierarchy as Drive.
How it works
Three steps, all of them on your device before anything reaches us.
Encrypted on your device
Every Drive client shares one Rust cryptography core. It derives keys from your passphrase and encrypts your files — and their names — locally. Your passphrase never leaves your device.
Only ciphertext reaches us
Encrypted chunks go straight to object storage over short-lived presigned URLs; file bytes never pass through our API. It handles authorisation and custody of wrapped keys — never plaintext.
You hold the only keys
Unlocking your account unwraps your master key on your device, from your passphrase. There is no server-side copy and no operator-side recovery.
Built for what comes after Drive
One crypto core, one identity model, one storage layer — designed to carry the same guarantee across Photos, Docs, and Mail as the suite grows, not bolted on product by product.
| Google Drive / Dropbox | "Encrypted" storage, typically | Drive | |
|---|---|---|---|
| Server can read your files | Yes | Sometimes — often at rest only | Never |
| Who holds the keys | The provider | Provider, via a recovery flow that quietly reintroduces one | You, always |
| Content used for ads / training | Yes, commonly | Varies, undisclosed | Can't — no plaintext to use |
| Crypto implementation | Closed | Closed, unauditable | One open, auditable Rust core |
What we can see — and what we can't
We publish exactly what the service has access to, including the parts that are not flattering: the browser is the weakest way to use Drive, file sizes and timestamps stay visible, and our identity provider sees signup emails and IP addresses.
Your files. Your keys. Not ours to lose.
Start with the web app, move to desktop when it ships — the same crypto core, the same account, either way.