Solution
Privasys Drive
End-to-end encrypted file storage where the operator holds no key, and you can prove it. Your files are sealed inside an attested confidential enclave, unlockable only by you. And when you connect Privasys Chat, that same sealed store becomes your assistant’s memory: a self-sovereign brain that answers only to you.
Your files, sealed to hardware you can verify.
The operator holds no key
Every file is encrypted with its own key, wrapped under a master key that is generated inside the enclave and split across a vault constellation. In sovereign mode only the attested Drive enclave, acting for you, can reconstruct it. There is no operator key and no operator unlock path.
Sovereign or escrowed, and checkable
Individuals get sovereign mode by default. Organisations can opt into an escrowed mode with quorum-approved, audited, tenant-disclosed recovery. The mode is part of the measured configuration, so you attest an instance and read back which promise governs your keys.
A brain you own
Connect Privasys Chat and your Drive becomes the assistant’s memory. Conversations, notes, and knowledge are all sealed files. The assistant reaches them only as an attested tool, over a mutually attested channel, and only within a scope you set.
Memory that is complete, and cited
Your memory is served as an enumerable tree, so the assistant sees everything it knows before it answers, never a lucky sample. Documents are chunked along a stable structure, so every passage it uses resolves to a real span in a real file and can be cited.
Personal or per project
Scope a brain to your whole Drive for a personal assistant that knows your history, or to a single folder for an agent that sees exactly one project and nothing of your private life. Share the folder and the brain is shared, still sealed to the enclave.
Sharing without giving up identity
Share a file with a link, and Privasys never learns who opened it. Opening a shared file proves a wallet identity and nothing more, no name and no email, unless a private link explicitly asks for an attribute.
Read the details.
The encryption, the key hierarchy, and the difference between sovereign and escrowed mode are covered in depth in the documentation and in two companion essays: one on the storage layer, one on turning the Drive into a self-sovereign memory for agents.