Trust Center

Security

End-to-end encryption starts on your device. Your file contents and names reach our servers encrypted, and we do not hold the secrets needed to read them. Explore passkeys, recovery and the limits of these protections.

End-to-end encrypted, before upload

After you unlock your drive, files are encrypted automatically on your device before upload. File contents, file and folder names, and sensitive application metadata are encrypted. InfiniDrive stores ciphertext and encrypted key records, so we technically cannot read the contents of your E2E-encrypted files.

Content uses authenticated AES-256-GCM streaming encryption with a fresh key for each file revision. Names and application metadata use AES-256-GCM. Your device verifies encrypted content before releasing decrypted bytes, and signed records bind files to their identity and version.

Your keys, your recovery

Your browser generates your encryption keys locally. A separate encryption passphrase protects them using Argon2id and encrypted key wrapping; a locally generated recovery key provides another way to unlock them. Only encrypted key records and public verification material reach the service. Setup requires you to save and verify your recovery key.

Keep your separate encryption passphrase and recovery key safe. Resetting your sign-in password does not decrypt your drive. If you lose all ways to unlock your keys, InfiniDrive cannot recover your encrypted file contents.

Passkeys for encrypted-file access

Use a passkey as an additional way to unlock your encrypted files after signing in. Confirm the request with your device’s fingerprint, face recognition or PIN, without entering your encryption passphrase each time.

After setting up file encryption, open File protection → Passkeys, create a passkey and verify it before it is added to your account. InfiniDrive receives only encrypted key records and public passkey metadata, never your biometric data or the secret that unlocks your file keys. Your files remain end-to-end encrypted.

Your encryption passphrase and recovery key remain available. You can remove a passkey from File protection to stop future unlocks through that saved record; this does not lock a session that is already unlocked. Removing the saved credential from your device’s passkey manager is a separate step. Keep your recovery key somewhere safe.

What the service can still see

End-to-end encryption protects file contents, names, and encrypted application metadata. It does not hide your account and billing details, IP addresses, object counts, ciphertext sizes, folder relationships, sharing records, or service timestamps. Ciphertext size can reveal a file’s approximate or exact original size. We process this operational data to run storage, access control, billing, and security.

Sharing stays end-to-end encrypted

Encrypted links share a read-only snapshot of selected files. The decryption secret stays in the link fragment after #, which is not sent to the service in the request. Recipients decrypt in their browser without an account and receive keys only for the selected file versions, never your account key. Treat the complete link as a secret: anyone who has it can open the shared files.

Links can expire or be revoked. Revocation stops future access through the service; it cannot recall files or keys a recipient has already saved.

Files open on your device

Downloads and supported previews are decrypted and verified locally. Supported Office documents open in an isolated browser editor, and saved changes are encrypted before upload. The server does not need readable file contents for these workflows. Locking your drive or signing out clears unlocked worker keys and decrypted previews.

Security you can inspect

The published source for our modified open-source components lets you inspect the encryption code and its release provenance. Source availability is not an independent security audit. Encryption depends on the integrity of your device and the application code your browser runs; it does not protect against a compromised device, a malicious browser extension, or a recipient keeping a downloaded copy.

European infrastructure

Primary compute and customer storage run in European data centers operated by Hetzner Online GmbH. Internal service traffic uses private networking where the platform supports it; public traffic enters only through controlled TLS endpoints fronted by Cloudflare.

Hosting in Europe keeps customer content under European data-protection law by default. It does not by itself make data immune to every legal process; the Privacy Policy describes how requests concerning data are handled.

TLS 1.3 in transit

All public InfiniDrive endpoints — the marketing site, the drive, the account panel, and the status page — use TLS 1.3 with automated certificate management and strict transport-security headers. Connections from outdated clients that cannot negotiate modern TLS are refused rather than downgraded.

Passkeys and optional two-factor authentication

Account sign-in also supports passkeys (WebAuthn), which you can add in your account’s sign-in settings. Sign-in passkeys and passkeys for unlocking encrypted files are set up separately: signing in does not automatically decrypt your files.

Every account can enable time-based one-time passwords (TOTP) in security settings: scan a QR code with any standard authenticator app, confirm one code, and from then on sign-in requires both your password and a current code. Active sessions can be reviewed and revoked from the same settings.

  • Passwords are stored only in hashed form; the control plane never keeps them in plaintext.
  • 2FA is optional today. Losing both password and authenticator makes account recovery deliberately slow — store recovery information safely.

RAID-backed storage redundancy

Customer files live on storage arrays with RAID-level redundancy, engineered to survive individual disk failures without data loss or downtime. Metadata and service databases run on separate managed block storage appropriate to their workload.

Automated service monitoring

Automated health checks continuously probe the drive, the account panel, and supporting services. Results feed the public status page at status.infinidrive.app, which anyone can read without an account, and alert the operations team when a check fails. Request identifiers let support trace individual incidents without exposing credentials.

Availability and change control

The platform is engineered to support hundreds of thousands of users: capacity is added ahead of demand, workloads are declaratively managed, and every production change is versioned and reviewed before rollout. These practices reduce operational risk; they do not eliminate every outage scenario, which is why the status page and incident history stay public.

No content scanning or data partnerships

We do not sell personal data or scan file contents for advertising or profiling. E2E encryption makes your encrypted file contents unreadable to InfiniDrive and its storage providers because they do not hold the decryption secrets. Account and operational metadata remain subject to the Privacy Policy.

Report a security issue

Found a vulnerability? Send a description, the affected URL, reproduction steps, and impact to security@infinidrive.app. Please do not access data that is not yours, degrade the service, or publish an unresolved issue before we have had a reasonable chance to fix it. We confirm receipt and keep you informed of the resolution.