Free forever · No credit card · Your credentials never leave your browser

Keep control of your files in the cloud.

Cloud Enclave encrypts files in your browser before upload so only you can access them. Integrates with Google Drive, OneDrive, and Dropbox.

Your storage You choose where files live
0 bytes Plaintext on our servers
Free forever No credit card required

Why common cloud storage can expose your files

Many cloud services and workflows leave readable data on servers or rely on fragile setups. Here are the issues.

Google Drive, OneDrive & Dropbox

They control the encryption keys.

Because providers control keys, uploaded files can be accessed by the service, employees, or anyone who compromises them.

Traditional encryption apps

Hard to use, easy to break.

Traditional encryption tools require extra expertise and separate workflows, increasing the risk of user error or data loss.

"Zero-knowledge" marketing claims

Claims you can’t always verify.

Some vendors advertise "zero-knowledge" without transparent, client-side encryption. Cloud Enclave runs in-browser encryption you can inspect.

Private cloud storage in three simple steps

No setup. No expertise required. You get the security of military-grade encryption with an experience as simple as any cloud drive.

01

Connect your cloud vault in seconds

Connect your Google Drive, OneDrive, or Dropbox account in seconds. Cloud Enclave requests only the bare minimum permissions to store and retrieve your encrypted files — nothing else.

Minimal permissions · Multi-account · No data collected
02

Your browser locks the file — not our servers

Before a file leaves your device it is encrypted in your browser using your password. We do not have access to the original file, your password, or the key used to lock it.

Encrypted on-device · Password stays local · Only locked data is transferred
03

Locked files go to your vault. You hold the key.

The encrypted file lands in your own cloud storage. When you retrieve it, your browser decrypts it locally using your password so readable data does not pass through our servers.

Stored in your vault · Decrypted in your browser · Readable data does not pass through us

Privacy-first features

Cloud Enclave keeps files private while staying easy to use.

Your files stay in your cloud, encrypted

Files are encrypted in your browser and stored in your cloud account; we do not have access to plaintext.

Credentials never leave your device

Sign-in happens client-side so your password isn't transmitted to our servers.

Compromise of one file won't expose the rest

Each file uses its own key so a single breach doesn't cascade across your vault.

Tamper detection built in

Files are signed on upload so integrity issues are detected before opening.

Decrypted only in your browser

Readable files are produced locally in your browser; servers only see encrypted data.

Multiple cloud accounts, one view

Connect Google Drive, OneDrive, or Dropbox; each appears as its own encrypted vault.

Reliable large uploads

Background uploads with progress and notifications for big folders.

Revoke access quickly

View and revoke active sessions to cut off access if a device is lost or shared.

Clear protection markers

Encrypted files have a clear extension so protected files are easy to spot.

Security-first design.
Built for everyone.

Our cryptographic stack is implemented in Rust, compiled to WASM, and runs exclusively in your browser. Here's exactly how it works.

AES-256-GCM

Authenticated encryption with unique IVs per chunk. Provides both confidentiality and integrity — any tampering is detected before decryption.

Argon2id Key Derivation

Argon2id (64 MiB memory · 3 iterations · parallelism 1) derives your encryption key from your password. The memory-hard design resists GPU and ASIC brute-force attacks. The derived key stays in your browser.

HMAC-SHA2 Challenge Auth

Zero-knowledge login: the server issues a nonce, your browser responds with an HMAC proof so the server can verify knowledge of the password without it being transmitted.

Rust WASM — No JS Crypto

Cryptographic operations run in a compiled Rust WASM module via a Web Worker. Native performance, constant-time operations, and avoids common pure‑JS crypto pitfalls.

app.cloud-enclave.com

Uploading file

annual-report.pdf 12.4 MB · selected
Deriving encryption key From your password · stays in browser
Encrypting file AES-256 · 2 chunks · unique keys
Uploading to your vault Sending encrypted data only…
Upload complete Server received only encrypted data
Encryption runs in your browser — we do not have access to plaintext
0 -bit
Encryption key length
0 MiB
Argon2id memory cost
0 bytes
Plaintext on server

Don't take our word for it.
Verify it yourself.

We built Cloud Enclave on a simple principle: you shouldn't have to trust us. The encryption is transparent, the libraries are open-source, and the proof is in your browser's network tab.

Audited open-source crypto

Our encryption runs on RustCrypto — independently audited, battle-tested libraries used by millions of projects worldwide. We wrote zero novel cryptography.

Read the NCC Group audit →

No VC funding. No data incentive.

Cloud Enclave is bootstrapped. We have no investors demanding growth at any cost, no advertising business model, and no reason to monetize your data.

Verify it yourself

Open Developer Tools in your browser while uploading. You won't see plaintext in network requests — only encrypted bytes. The client-side encryption is observable, not just stated.

Your files live in your own cloud storage

We don't host your files — they live in your own connected storage account. You own the storage, you control the account, and your encrypted files are always accessible to you directly.

We didn't invent our own cryptography — we built on the same battle-tested libraries trusted by millions of projects worldwide.

Photo of Łukasz Czerniawski
Łukasz Czerniawski Founder & Engineer
I built Cloud Enclave because I needed it myself — I wanted the cloud to handle my files, but I wasn't willing to let it see what was inside them."

I'm a software architect with a background in web applications and security. After spending years watching "zero-knowledge" become a marketing buzzword with nothing behind it, I decided to build something that invites you to verify every claim in real time — straight from your browser's DevTools. Cloud Enclave is bootstrapped, independent, and built to earn your trust one auditable detail at a time.

Start free. Upgrade when ready.

One vault to start. Unlock everything when you're ready. No credit card required — pro features are in development, join the waitlist for early access.

Free

$0 /forever

Everything you need to keep your personal files private — no strings attached.

  • 1 vault (any supported provider)
  • Unlimited encrypted files
  • Military-grade encryption
  • Password never leaves your device
  • Revoke cloud access anytime
  • Community support
Get Started Free
Coming soon

Enclave

$8 /per month

For people who take privacy seriously — across every provider, every account, every device.

  • Unlimited vaults
  • Any supported provider per vault
  • Everything in Free
  • Priority email support
  • Early access to new features
  • Encrypted cross-device sharing
Join the Waitlist

All plans use the same encryption.

Your files deserve privacy.
Start free today.

No credit card. No limits on encrypted files. Connect your cloud vault in under a minute — and take back control of your data.

Your password stays in your browser. We do not have access to readable file contents.

Frequently asked questions

Have a question not answered here? Send us feedback.

Can Cloud Enclave read my files?

No. Files are encrypted in your browser before upload and the key is derived from your password, which stays on your device. We store only encrypted data and do not have the key to decrypt it.

What happens if I forget my password?

If you forget your password, we can't recover it because we don't hold your encryption key. We recommend storing your password in a password manager (Bitwarden, 1Password) or exporting recovery material. Passkey support is on our roadmap.

Where are my files actually stored?

Encrypted files are stored in your own cloud storage account, whether that is Google Drive, OneDrive, or Dropbox. Cloud Enclave stores only encrypted file metadata (filename hash, size, encryption parameters) in our database — never file content. You remain the owner of the storage.

What encryption does Cloud Enclave use?

The same standard used by governments, banks, and militaries worldwide — AES-256. On top of that, every file is authenticated, meaning if anyone tampers with even a single byte, the file will refuse to open. Your encryption key is produced from your password using a memory-hard algorithm specifically designed to make brute-force attacks computationally impractical. For the technically curious, the full stack is detailed in the Security section.

Can I connect multiple accounts or providers?

Yes. On the free plan, you get one vault connected to any supported provider. Upgrade to connect unlimited vaults across as many accounts and providers as you need. Each appears as a separate encrypted vault in the sidebar with its own OAuth connection and session tokens. You can revoke access to any vault independently. Google Drive, OneDrive, and Dropbox are supported today.

How does login work without sending my password?

Cloud Enclave uses a zero-knowledge challenge-response protocol. When you log in, the server issues a random nonce and a bcrypt salt. Your browser computes a bcrypt hash of your password with that salt, then produces an HMAC-SHA512 proof using the nonce. The server verifies the proof without ever seeing your password or your encryption key.

Will I always have to type a password for each file?

Not forever. Right now you provide a password each time you lock or unlock a file — that password is used to derive the encryption key on the spot. Passkeys are on our roadmap: your device (Face ID, Touch ID, Windows Hello, or a hardware key) will derive that key automatically, so your vault opens without typing anything. The zero-knowledge guarantee stays intact — the key still never leaves your browser. Existing password-based vaults will have a migration path when passkey support launches.

Is the encryption code auditable?

Yes. The Rust cryptography implementation in our WASM module uses well-audited crates: aes-gcm 0.10, argon2 0.5, and hmac + sha2 from the RustCrypto project. These are open-source libraries with independent security audits.

What data does Cloud Enclave store about me?

We store your username, a one-way hash of your login credentials (never your actual password), encrypted file metadata, cloud storage access tokens, and session tokens. We never store your encryption key or any readable file content. Your files themselves live in your own connected cloud storage.