Micron Document
Tcf362fT131417 PRIVACY GUIDES T969389~/privacy
T969389Cloud Storage

Tcf362fhome Tcf362fsearch Tcf362flfm index
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────

T969389Sections: Tcf362fProton Drive Tcf362fTresorit Tcf362fPeergos Tcf362fCriteria

Protects against the following threat(s):


Many cloud storage providers require your full trust that they will not look at your files. The alternatives listed below eliminate the need for trust by implementing secure end-to-end encryption.

If these alternatives do not fit your needs, we suggest you look into using encryption software like Tcf362fCryptomator with another cloud provider. Using Cryptomator in conjunction with any cloud provider (including these) may be a good idea to reduce the risk of encryption flaws in a provider's native clients.


For more technical readers, Nextcloud is Tcf362fstill a recommended tool for self-hosting a file management suite, however we do not recommend third-party Nextcloud storage providers at the moment, because we do not recommend (https://discuss.privacyguides.net/t/dont-recommend-nextcloud-e2ee/10352/29) Nextcloud's built-in E2EE functionality for home users.


Proton Drive


Proton Drive is an encrypted cloud storage provider from the popular encrypted email provider Tcf362fProton Mail.

The initial free storage is limited to 2 GB, but with the completion of certain steps (https://proton.me/support/more-free-storage-existing-users), additional storage can be obtained up to 5 GB.

Homepage (https://proton.me/drive)


* Google Play (https://play.google.com/store/apps/details?id=me.proton.android.drive)
* App Store (https://apps.apple.com/app/id1509667851)
* Windows (https://proton.me/drive/download)
* macOS (https://proton.me/drive/download)


The Proton Drive web application has been independently audited by Securitum in 2021 (https://proton.me/community/open-source), but the brand new mobile clients have not yet been publicly audited by a third party.


Tresorit


Tresorit is a Swiss-Hungarian encrypted cloud storage provider founded in 2011. Tresorit is owned by the Swiss Post, the national postal service of Switzerland.

Homepage (https://tresorit.com)


* Google Play (https://play.google.com/store/apps/details?id=com.tresorit.mobile)
* App Store (https://apps.apple.com/app/id722163232)
* Windows (https://tresorit.com/download)
* macOS (https://tresorit.com/download)
* Linux (https://tresorit.com/download)


Tresorit has received a number of independent security audits:

* 2022 (https://tresorit.com/blog/tresorit-receives-iso-27001-certification): ISO/IEC 27001:2013[1] Compliance Certification (https://certipedia.com/quality_marks/9108644476) by TÜV Rheinland InterCert Kft
* 2021 (https://tresorit.com/blog/fresh-penetration-testing-confirms-tresorit-security): Penetration Testing by Computest
* This review assessed the security of the Tresorit web client, Android app, Windows app, and associated infrastructure.
* Computest discovered two vulnerabilities which have been resolved.
* 2019 (https://tresorit.com/blog/ernst-young-review-verifies-tresorits-security-architecture): Penetration Testing by Ernst & Young.
* This review analyzed the full source code of Tresorit and validated that the implementation matches the concepts described in Tresorit's white paper (https://prodfrontendcdn.azureedge.net/202208011608/tresorit-encryption-whitepaper.pdf).
* Ernst & Young additionally tested the web, mobile, and desktop clients. They concluded:

Test results found no deviation from Tresorit’s data confidentiality claims.

[1] ISO/IEC 27001 (https://en.wikipedia.org/wiki/ISO/IEC_27001):2013 compliance relates to the company's information security management system (https://en.wikipedia.org/wiki/Information_security_management) and covers the sales, development, maintenance and support of their cloud services.

They have also received the Digital Trust Label, a certification from the Swiss Digital Initiative (https://efd.admin.ch/en/swiss-digital-initiative-en) which requires passing 35 criteria (https://swiss-digital-initiative.org/criteria) related to security, privacy, and reliability.


Peergos


Peergos is a decentralized protocol and open-source platform for storage, social media, and applications. It provides a secure and private space where users can store, share, view, and edit their photos, videos, documents, etc.

Peergos secures your files with quantum-resistant E2EE and ensures all data about your files remains private. It is also self-hostable (https://book.peergos.org/features/self).

Homepage (https://peergos.org)


* Google Play (https://play.google.com/store/apps/details?id=peergos.android)
* GitHub (https://github.com/Peergos/web-ui/releases)
* Windows (https://peergos.org/download#windows)
* macOS (https://peergos.org/download#macos)
* Linux (https://peergos.org/download#linux)
* Web (https://peergos.net)


Peergos is built on top of the InterPlanetary File System (IPFS) (https://ipfs.tech), a peer-to-peer architecture that protects against Tcf362fCensorship.

The client, server, and command line interface for Peergos all run from the same binary. Additionally, Peergos includes a sync engine (https://book.peergos.org/features/sync) (accessible via the native apps) for bi-directionally synchronizing a local folder with a Peergos folder, and a webdav bridge (https://book.peergos.org/features/webdav) to allow other applications to access your Peergos storage. You can refer to Peergos's documentation for a full overview of their numerous features.

Peergos was audited (https://peergos.org/posts/security-audit-2024) in November 2024 by Radically Open Security and all issues were fixed. They were previously audited (https://cure53.de/pentest-report_peergos.pdf) by Cure53 in June 2019, and all found issues were subsequently fixed.


Criteria

Please note we are not affiliated with any of the projects we recommend. In addition to Tcf362four standard criteria, we have developed a clear set of requirements to allow us to provide objective recommendations. We suggest you familiarize yourself with this list before choosing to use a project, and conduct your own research to ensure it's the right choice for you.


Minimum Requirements

* Must enforce E2EE.
* Must offer a free plan or trial period for testing.
* Must support TOTP or FIDO2 multifactor authentication, or passkey logins.
* Must offer a web interface which supports basic file management functionality.
* Must allow for easy exports of all files/documents.


Best-Case

Our best-case criteria represents what we would like to see from the perfect project in this category. Our recommendations may not include any or all of this functionality, but those which do may rank higher than others on this page.

* Clients should be open source.
* Clients should be audited in their entirety by an independent third party.
* Should offer native clients for Linux, Android, Windows, macOS, and iOS.
* These clients should integrate with native OS tools for cloud storage providers, such as Files app integration on iOS, or DocumentsProvider functionality on Android.
* Should support easy file sharing with other users.
* Should offer at least basic file preview and editing functionality on the web interface.


──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
Tcf362fHome Tcf362fWiki Tcf362fTG Series Tcf362fChat Tcf362fArticles Tcf362fContact

Ta6a49eContent from Privacy Guides (privacyguides.org), commit 0295ab4.
Ta6a49eLicense: CC BY-SA 4.0 - creativecommons.org/licenses/by-sa/4.0