Photon Vault

Your cloud drive, divided by design.

Replace your cloud drive with a private place for your complete file collection. Create client-side encrypted Vaults for the files, people, and projects you want to keep isolated.

A cloud drive, not a transfer tier.

Photon Transfer, including Live Relay and File Passes, moves files now. Photon Vault keeps them: a client-side encrypted cloud drive for the files you use every day. Storage is based on how much you keep, not the size of an individual file. Paid Vault storage scales beyond the included amount at $0.04/GiB-month and has no fixed capacity limit. Vault Free has 10 GiB included, a hard 10 GiB limit, and no paid overage. Files expire seven days after upload.

Folders organize your files. Vaults isolate them.

Folders help people arrange files inside a Vault. Vaults are the hard privacy boundary: access, sharing, Vault Intake, encryption, and desktop sync are separate for each one.

Go deeper with the Vault guide and the technical security overview, or see how Vault Intake lands uploads inside the right Vault workflow.

Private by design

Files are encrypted locally before they leave your device. PhotonFile stores encrypted data, but does not hold the keys needed to decrypt your Vault contents.

Many isolated Vaults

Each Vault is its own hard privacy boundary. Keep personal files, work, financial records, projects, client data, teams, and family data in the Vaults that make sense for you.

Share without merging boundaries

Share a project or team Vault, send scoped links, or collect files through Vault Intake without opening your other Vaults or turning the server into the place where plaintext files live.

A cloud drive for everything you keep

Photon Vault is a private cloud drive for individuals and teams: store and sync your complete file collection, share access, and collect uploads without managing complex security infrastructure.

Traditional cloud storage puts everything behind one broad privacy boundary. With Vault, you choose where the hard boundaries go. Map different local folders and data sets to different Vaults, then collaborate in a shared Vault, share specific files or folders with scoped links, collect files through Vault Intake, and keep older versions when files are updated.

Client-side encryption by default

Before a file is uploaded to Photon Vault, it is encrypted locally on the client. Encrypted data is then transferred and stored in PhotonFile infrastructure as encrypted blobs.

  • Files are encrypted before leaving the device
  • Data remains encrypted during transfer and storage
  • Only authorized clients can decrypt vault contents
  • PhotonFile cannot read the contents of vault files

Post-quantum-ready key management

Photon Vault is built with a post-quantum-ready key management model designed for long-lived encrypted storage. Public-key operations used for protected access flows are built around modern post-quantum cryptography, while file data remains protected with strong client-side authenticated encryption.

For users, that means Vault is designed not only for today's security requirements, but also for long-term protection of the files they keep every day.

Secure collaboration

Teams can work together inside a shared Vault without exposing file contents to the server or opening unrelated personal, client, or project Vaults. Authorized members access Vault contents through their own approved clients.

Scoped sharing

Share links can be limited to specific files or folders inside a Vault and protected with options such as expiration, revocation, and usage limits without changing the boundary around your other Vaults.

Vault Intake

Vault owners can receive files from external users into the right Vault without giving them access to existing contents. This is useful for client submissions, evidence collection, intake flows, and secure document requests.

Learn about Vault Intake

Versioning

When a file is uploaded again at the same path, Vault stores a new version instead of overwriting the old one. This helps protect against accidental replacement and gives users more control over changes over time.

What PhotonFile can and cannot see

PhotonFile cannot see

  • The plaintext contents of files stored in a vault
  • The keys required to decrypt vault files
  • The plaintext contents of uploaded vault data
  • Plaintext filenames, folder names, and search queries for Maximum Privacy Vaults

PhotonFile can see limited service metadata

  • Account and service information needed to operate the service
  • Vault and object identifiers
  • Object counts, file sizes, timestamps, and transfer activity
  • Folder relationships, ACLs, share-link, and upload events
  • Private-search token frequency and access patterns

Need more detail?

Read the public Vault guide for step-by-step usage help, or open the technical security overview for a deeper explanation of key hierarchy, post-quantum-ready design goals, chunk encryption, scoped sharing, and Vault Intake security posture.