End-to-end encrypted document platform · EUEnd-to-end encrypted · EU
Your files.Your keys.Your tenant.
NomadVault encrypts every document in your browser before it leaves your device. We store ciphertext only and hold no key that could open it: no provider backdoor, no recovery key on our side. All of it hardened against future quantum computers with hybrid post-quantum cryptography.NomadVault encrypts every document in your browser before it leaves your device. We store ciphertext only, hardened against future quantum computers with hybrid post-quantum cryptography.
End-to-end encrypted (AES-256-GCM)End-to-end encrypted (AES-256-GCM)Post-quantum (ML-KEM-768, NIST FIPS 203)Post-quantum (ML-KEM-768)Hosted in the EUHosted in the EU
acme.nomadvault.de
The problem
Regulated data shouldn't depend on a vendor's trust.Regulated data shouldn't depend on a vendor's trust.
Encryption that doesn't encrypt
Provider-managed keys invalidate end-to-end encryption, reducing security to a contractual promise rather than a cryptographic guarantee. True control requires local key ownership; any entity holding the encryption keys remains a single point of failure subject to insider abuse, external compromise, or lawful interception.Cloud storage encrypts at rest but keeps the keys, and whoever holds the keys can be made to use them.
Harvest now, decrypt later
Adversaries already intercept and store encrypted data today so they can unlock it later using future quantum computers. Hybrid post-quantum key wrapping addresses tomorrow’s threats, today.Encrypted traffic is collected today to be decrypted once quantum computers arrive.
Compliance needs automation
Retention, legal holds, access audits and incident response are workflows, not folders. Storage that merely holds files leaves those obligations to people and spreadsheets, where deadlines slip and evidence goes missing. Compliance holds when rules run automatically on the data itself, every action is recorded, and the record cannot be edited afterwards.Retention, legal holds and access audits are workflows, not folders.
The platform
Four products, one encrypted core
Every product works on the same client-side keys. Nothing is decrypted outside your browser or your own device.
Vault
Contracts
v3 · v2 · v1
Shared link · viewer
Encrypted files and folders. Sharing with people and groups, roles for viewer, editor and co-owner, upload and download links, versioning, and search over blinded tokens the server matches but cannot read.Encrypted files, sharing, roles, links, versions and blind search.
Flow
When file added to /Legal
Classify · retain 10 y · alert
No-code automation on vault events: alerts, file moves, retention schedules and classification, without a developer.No-code automation on vault events: alerts, moves, retention, classification.
Compute
SELECT sum(amount) FROM invoices
Analytics, SQL and reports that run on decrypted data inside the browser. Results stay on your device unless you choose to save them to the vault, where they are encrypted like any other file, or export them.Analytics, SQL and reports on decrypted data, inside the browser; results leave it only when you save or export them.
Sync
Windowssynced
macOSsynced
Linuxsynced
A native desktop client for Windows, macOS and Linux. Familiar folder sync, with end-to-end encryption preserved.Native desktop client for Windows, macOS and Linux.
Isolation
Your own tenant. Not a shared database with a column for your company.
Each customer is deployed on their own. Separate subdomain, separate database, separate storage bucket, separate keys, so there is no data path where tenants can meet.
Browser
Account Master Key (one per user)
File keys · RSA-4096 + ML-KEM-768
AES-256-GCM encrypt / decrypt
Keys are generated and stay here. The password never leaves the device.
CiphertextTLS 1.3
Your tenant · acme.nomadvault.de
APIOwn databaseDirectory · SSOAudit log
Sees ciphertext, metadata envelopes and wrapped keys it cannot unwrap.
CiphertextPrivate network
Object storage
8f3a…c91 · 1.2 MB
a0d7…4be · 840 KB
c4e1…772 · 312 KB
Your own bucket, in Germany or Finland. Encrypted off-site backups.
BrowserKeys generated and kept here. Plaintext exists only in the browser.
Ciphertext ↓
Your tenant · acme.nomadvault.deAPI, own database, directory, audit log. Sees only ciphertext and wrapped keys.
Ciphertext ↓
Encrypted object storageYour own bucket in Germany or Finland. Encrypted off-site backups.
Plaintext exists only inside the browser box. Everything to the right of it is ciphertext, including search indexes and previews.
What the server can still see: file sizes, MIME types and timestamps, folder structure and the sharing graph (who has access to what), user identities and audit events, access patterns, and the blinded search tokens, meaning which tokens occur in which file and which files a query matches, never the words behind them. Not the file contents, file or folder names, or any private key.
IdentityOwn subdomain (yourcompany.nomadvault.de) or your own domainOwn branding, admin, user directory and SSO
IsolationOwn database and own encrypted storage bucketIsolated deployment; tenants never share data paths or keys
StorageOur EU bucket, or bring your own S3-compatible storage at any providerDurability, replication and retention set by your policy, not ours
OperationsEU hosting (Germany / Finland), operated by NomadVault, or self-hosted for Enterprise99.5% availability target per tenant, encrypted off-site backups
Nomad by design
Your data lives in the storage you choose.
The “nomad” in NomadVault is the storage layer. Every tenant writes its ciphertext to an S3-compatible bucket, and that bucket can be one we provision for you or one you bring yourself: at any provider, in any region, with the durability, replication, retention and cost profile your own policy demands.
Backups follow the same rule: encrypted with a key you hold, written to a bucket in the same jurisdiction.
Any S3-compatible providerAWS S3, Hetzner Object Storage, IONOS, Wasabi, or a MinIO cluster in your own data centre. You enter endpoint, bucket and credentials in the tenant settings; NomadVault never needs more than write and read on that bucket. Your monthly base price drops accordingly, since we no longer operate storage for you.
Your durability and residency rulesChoose the storage class, cross-region replication, object lock and lifecycle rules that match your retention obligations. The tenant has no opinion about them; it only ever stores opaque ciphertext blobs.
The provider sees nothing usefulBecause file content, names and search tokens are encrypted before upload, the storage provider only holds random identifiers and ciphertext. Trust in the bucket is reduced to availability and durability, not confidentiality.
Move without re-encryptingObjects are addressed by identifier, not by provider. Switching buckets or providers is a copy of ciphertext plus a settings change; keys and grants do not change.
Security
Security, explained honestly
What we do, in the terms your security reviewer will use. No superlatives, no claims we cannot evidence.
PDF, 9 pages · what we protect, what we can see, what it means for you. Technical whitepaper on the security page.
Client-side AES-256-GCMFiles are encrypted before upload; the server stores ciphertext.
Hybrid key wrappingRSA-4096 plus ML-KEM-768 for every file key.
Account Master Key, per userEach user derives their own master key in the browser from their password. There is no tenant-wide key that could unlock everyone's files.
Signed sharing grantsEd25519 signatures with key pinning per recipient.
Passkeys, MFA, SSOMicrosoft Entra SSO and scoped service-account API keys.
Optional escrow keyYours, not ours: off by default, generated and held by you, every use audited. We hold no recovery key of any kind.
Content Disarm & ReconstructionActive content is stripped from uploads on the client.
Tamper-evident audit logHash-chained entries with bulk-activity alerts.
On-device AI onlySummaries and translations run on the model built into the browser. No text is sent to us or to any AI service.
Encrypted backups, EU hosting, GDPR-alignedWorking towards ISO 27001 and BSI C5; current status published on the security page.
In detail
What the encrypted core lets you do
Encrypted full-text search
Your browser tokenises file names and text content, keys each token with a per-user search key and sends only those blind tokens to the index. A query is transformed the same way, so the server matches tokens it cannot read. The search key itself is stored hybrid-wrapped (RSA-4096 + ML-KEM-768) like every other key. What the server does learn: which blinded tokens occur in which file, how often they repeat and which files a query matched: patterns, not words.
Why it matters Search is where most “zero-knowledge” products quietly leak: a plaintext index on the server reveals every word in every document. Here the index is as blind as the storage, and we say plainly what it still reveals.
Content Disarm & Reconstruction on upload
Before a document is encrypted, the client strips macros, scripts, embedded objects and active content from Office and PDF files and rebuilds a clean copy. Legacy binary Office formats that cannot be sanitised are refused, and if sanitising fails the upload stops rather than passing the original through.
Why it matters A server that only ever sees ciphertext cannot run a virus scanner. Cleaning documents where the plaintext exists, in the browser, closes the door on macro malware arriving through shared client files. It removes active content; it is not a malware scanner and does not detect every threat, so endpoint protection with up-to-date antivirus on every device that opens files remains part of the picture.
Chunked, streamed and retried uploads
Every file is encrypted in 10 MB chunks with a unique nonce per chunk and the chunk index bound into the authentication tag, so a chunk cannot be reordered, dropped or swapped without the client noticing. The last chunk is padded to a size bucket, which hides exact file sizes from the storage provider. Files above 5 MB travel as independent parts through the storage provider's multipart API, and throttled requests are retried automatically with backoff, so bulk uploads survive rate limits instead of failing on the first rejected part. Downloads decrypt chunk by chunk as they stream, in the browser, in the sync client and in the macOS app.
Why it matters End-to-end encrypted storage is only useful if a 4 GB scan set from a client actually arrives. Chunking makes large uploads survive real networks, streaming means nothing has to be buffered in memory, and the authenticated chunk index turns a truncated or tampered object into a hard error instead of a silently corrupted document.
Encrypted notes next to your files
Write a note directly in the vault, in the folder it belongs to, without leaving the browser. Notes are stored exactly like files: encrypted client-side, versioned, classified, shareable with the same roles and covered by the same audit trail.
Why it matters The context around a document, such as a call summary, a decision or the reason a file was shared, usually ends up in e-mail or a chat tool where none of these guarantees apply. Keeping it in the vault keeps the whole record in one protected place.
AI that runs on your device, not on a server
Summarise a note or a document, translate it, or create a translated copy of a Word, PowerPoint or OpenDocument file that keeps its formatting: all of it with models that run inside your browser. NomadVault uses the on-device model and language packs built into Chrome (Gemini Nano): the browser downloads them once from the browser vendor and then runs them locally, so the text you process never reaches us, the browser vendor or any AI service. The translated copy is encrypted and saved next to the original like any upload. These actions only appear in browsers that ship such models (currently desktop Chrome); everywhere else they are simply absent rather than routed to a cloud.
Why it matters Every “AI assistant” in cloud storage works by sending your documents to a model somewhere else, which is the exact data path end-to-end encryption exists to close. In this architecture plaintext exists in one place, the browser, so that is the only place a model is allowed to run. We would rather offer no AI in a browser without a local model than open a side channel to keep up with a feature list.
Versioning and recovery
Every upload of an existing file creates a new encrypted version with its own key. Earlier versions stay restorable by anyone with access to the file, and folder trees can be recovered after an accidental delete.
Why it matters Ransomware and human error overwrite files. A version history that the attacker cannot decrypt or purge is the difference between an incident and a restore.
Signed sharing grants with key pinning
When you share a file or folder, your browser re-wraps the key for the recipient and signs the grant with your Ed25519 key. Recipients pin the public keys of the people they work with on first use and reject grants that do not verify.
Why it matters The classic attack on end-to-end encryption is a server swapping in its own public key. Signatures and pinning turn that swap into a visible error instead of a silent compromise.
Upload and download links
Hand an external party a link and they can drop files into a folder, or fetch a document, without an account. Files are encrypted in their browser before transfer and the link can carry an expiry and a password.
Why it matters Client intake by e-mail attachment is how confidential documents end up in mailboxes and backups you do not control. Links move that traffic into the vault.
Tamper-evident audit log
Every access, share and admin action is written to a hash-chained log whose head is verifiable from the settings page. Retention is a tenant setting (365 days by default), purges are re-anchored and attested, and bulk-activity alerts flag mass downloads.
Why it matters Regulators and clients ask who saw what and when. An audit trail is only evidence if it can be shown that nobody edited it afterwards.
Passkeys, MFA, SSO and service accounts
Sign in with passkeys or a password plus MFA, or through Microsoft Entra single sign-on. Automation uses service accounts with scoped API keys instead of a person's credentials, and every session carries its own post-quantum key material.
Why it matters Phishing-resistant login protects the one thing the architecture cannot: the user's device and password. Scoped keys keep integrations from becoming a back door.
Automated classification of file content
When classification is enabled, the browser scans each text-based document before encrypting it and tags it with the categories it detects: personal data under the GDPR, health data, financial data, credentials and secrets, plus patterns you define yourself such as client numbers or project codes. The result is stored with the file, shown in the properties panel and the compliance report, and can be corrected by anyone with edit rights, with every change audited. Binary formats are not scanned, and nothing about the scan leaves the device except the resulting labels.
Why it matters You cannot apply retention, access rules or a DPIA to documents you have not identified. Server-side classifiers would need plaintext, which this architecture refuses to hand over, so the scan happens in the only place the plaintext exists. The labels then drive Flow rules automatically: a file tagged as health data can be moved, retained and flagged the moment it arrives.
Expiry, retention and automatic deletion
Files and folders can carry an expiry date with an action: delete, archive or notify. Flow rules apply retention schedules by folder or by classification, and the compliance report lists every document with its classification, expiry and the action that will follow. Deletions run on schedule and are recorded in the audit log.
Why it matters Retention obligations cut both ways: keep records for the statutory period, and stop keeping them afterwards. Doing that by hand across thousands of client files does not happen; doing it by rule, with an audit entry for every deletion, is what an auditor wants to see.
Access rights for groups, not just people
Create groups such as “Tax team” or “Board” and share folders with a group the same way you share with a person, with the same viewer, editor and co-owner roles. Each group has its own key pair: a share to the group is one grant sealed to the group key, and members receive the group key wrapped for their own keys. Group leads manage membership themselves; adding someone gives them everything the group can see, and removing them rotates the group key so they are cryptographically cut off rather than merely hidden.
Why it matters Sharing with individuals does not survive staff changes: every join and leave means touching dozens of folders. Groups turn access management into membership management, which is how your organisation already thinks, and keep the encryption honest when people move on.
Desktop sync that stays encrypted
The native client for Windows, macOS and Linux shows your vault as a normal folder. Files appear as placeholders and are fetched and decrypted only when opened, so a large vault costs no local disk until you need it. Keys never leave the device, and an optional remembered login is kept in the operating system keystore.
Why it matters Encryption that only works in a browser gets bypassed the moment someone needs a file in Explorer or Finder. Sync brings the same guarantees to the place people actually work.
Customer-controlled escrow key
Optional and off by default. If you enable it, your organisation generates an escrow key pair in the browser and keeps the private half; file keys are additionally wrapped to it, and every use of the escrow key is recorded in the audit log. If you never enable it, no such key exists anywhere.
Why it matters Many products marketed as end-to-end encrypted quietly hold a recovery or escrow key themselves. It is how they reassign a leaver's files or reset a forgotten password, and it is rarely spelled out on their security pages. A key like that makes the provider able to read your data, whatever the brochure says. NomadVault has none. People still leave and passwords still get lost, so escrow exists as an option you create, hold and audit yourself.
A look inside
The product, not a mockup
Screenshots from a NomadVault tenant with demo data. Every screen shown here works on ciphertext the server cannot read; what you see is decrypted in the browser at the moment it is displayed.
Click to enlarge
File properties with classificationContent encrypted with AES-256-GCM and verified, the file key wrapped with RSA-4096 plus ML-KEM-768, a checksum, and the classification the browser assigned on upload: financial data, personal data and a custom pattern.
Click to enlarge
Sharing with a roleAdding a member to a file: the recipient's address, a viewer, editor or co-owner role, and one grant per member with the file key sealed to each of them.
Click to enlarge
A workflow reacting to classificationThe “Sensitive File Alert” template: triggered when a file is classified as personal, health, financial or credential data, sending a notification without anyone reading the file.
Click to enlarge
Classification settingsCategories can be renamed or switched off, and custom patterns such as client names or project codes are matched in the browser before encryption.
Click to enlarge
Audit log retention and tamper evidenceRetention is a tenant setting with a documented default of 365 days, IP logging is off unless consented, and the whole hash chain can be verified from here.
Click to enlarge
The vaultFolders, files, owners and timestamps in a familiar list. Names are encrypted at rest and decrypted for display; the search box on the left queries an index the server cannot read.
Who it is for
Built for teams that answer to a regulator
Legal and tax advisors
Professional secrecy under §203 StGB, with client files never readable by a provider.
Healthcare and research
GDPR Art. 9 special-category data and study documents with strict access records.
Finance and insurance
DORA obligations on ICT risk, exit plans and evidence of resilience.
Public sector and NGOs
NIS2 duties and EU-only data residency, with self-hosting where required.
Engineering teams with IP
Trade-secret protection for drawings, specifications and source documents.
Pricing
Per tenant, per month, in euro
Every plan starts with a free 14-day trial tenant: 10 users, 100 GB, no credit card.
Starter
€29/ month
5 users and 250 GB included
Each additional user €5 / month · each additional GB €0.10 / month
Built in Germany, hosted in the EU · No credit card for the trial · Cancel any time
Cookies for analytics. We would like to use Google Analytics to understand how this website is used. It only runs if you accept, and you can change your mind on the privacy page. Privacy