Nobody reads your files. Not even us.
Every file is encrypted on your device before it leaves it. We hold the ciphertext and none of the keys — that is maths, not a promise.
Your files are yours alone
End-to-end encryption and a zero-knowledge design mean no one — not even Offkeep — can read what you store.
Everything you need to keep your files private
End-to-end encryption
Every file is encrypted on your device before upload with ChaCha20-Poly1305. The ciphertext is the only thing that ever touches our servers — we never see your plaintext.
Zero-knowledge architecture
Your master key is a random 256-bit key generated on your device and wrapped by your password. Key material never leaves your device — even if our infrastructure were fully compromised, your data would remain unreadable.
No surveillance
We don't scan, index, or analyse your files. No ad targeting, no usage profiling. Your private files stay private — full stop.
Sovereign infrastructure
Your ciphertext lives in European data centres with physical access controls, redundant power, and network isolation — in the European Union (the Netherlands).
Verifiable integrity
Every file is encrypted with authenticated encryption, and integrity is verified as it is decrypted. Tampering or corruption is detected automatically and the file fails closed before you open it.
Secure sharing
Shared folders are protected by keys sealed to each member’s device — we store only the sealed copies. Shared links are protected by a random token that only the link holder can use.
Your password unlocks a chain of keys
Your password never encrypts your files directly. It unlocks a master key, which wraps folder keys, which wrap a fresh key for every file — so only ciphertext and wrapped keys ever reach our servers.
Password
or passphrase
KEK
scrypt · never stored
Master Key
random 256-bit
Folder Keys
chained per folder
Data Keys
one per file
ChaCha20-Poly1305
8 MiB chunks · AEAD
Ciphertext
file bodies
Offkeep servers
wrapped keys + ciphertext only
even a breach reveals nothing
Encryption at every step
Key derivation
Your password is run through a slow, memory-hard KDF (scrypt) to produce a key-encryption key. The server stores only the salt and the wrapped copy — never the key itself.
Client-side encryption
Before upload, your file is encrypted with a fresh random key using ChaCha20-Poly1305. That per-file key is wrapped by its folder key, and only the wrapped copy is stored alongside the ciphertext.
Secure transfer
Encrypted data travels over TLS 1.3, so even the ciphertext is protected in transit. Because your files are already end-to-end encrypted, a compromised connection still reveals nothing.
At-rest storage
Ciphertext is additionally encrypted at rest by our storage provider — a second layer of protection even if raw storage were accessed.
Folder keys for any number of people
Every member has a keypair — a public key others seal keys to, and a private key that never leaves their device. A shared folder's key is sealed once per member, so sharing scales without re-encrypting files — and the owner decides who's in, and what each member can do.
Create shared folder
Share Key
random 256-bit · on device
Sealed boxes
one per member · X25519
Members decrypt
private keys stay on device
Change access?
owner or manager
Manage access
Invite · seal for their pub key
Re-role · roles + per-member caps
Remove · sealed box deleted
Rotate · re-seal for the rest
Access unchanged
nothing re-encrypted
Offkeep never sees the keys
A recovery password wraps your private key for new-device restore — still ciphertext only.
Security FAQ
Can Offkeep read my files?
No. Encryption and decryption happen exclusively on your device. We only store ciphertext and have no access to your keys.
What happens if I forget my password?
Because we operate a zero-knowledge model, we cannot reset or recover your master key. We offer an encrypted recovery key you can store offline during sign-up.
Is the encryption code audited?
Our cryptographic implementation is open-source, so anyone can inspect exactly how your data is protected. We are committed to commissioning independent third-party audits and will publish the reports here once they are complete.
How are shared links secured?
Shared folder keys are sealed to each recipient’s public key, and we store only the sealed copies — so we cannot decrypt content shared with you. Shared links use a random token that only the link holder can use.