Zero-knowledge file delivery for software
Upload a build, a whole folder or a config value. Your browser encrypts and signs it before it leaves your computer, Vaultix stores and delivers only encrypted data, and only your app unlocks it.
We can’t read your files
The keys stay with you, the team members you approve and your app. A database leak, a stolen backup or a demand to hand over your files gets encrypted data only.
Nobody can swap them
Every upload is signed by the person who made it. Your app checks the signature, the size and the SHA-256, and refuses anything else, even a file that came from our servers.
Only your customers receive them
- Downloads need a signed-in user with an active subscription to that product
- Every download is encrypted again with a key that exists only for that request
- The SDK decrypts in memory, so a build can run without being written to disk
- Folders keep their structure, straight from a ZIP
More than files
Product variables, such as a server address or a feature flag, are encrypted the same way and change your app’s behaviour without a new build.
Questions
- What does zero-knowledge mean here?
- Vaultix stores and delivers your files but holds no key that opens them. Only you, the team members you approve and your app can decrypt them.
- What does Vaultix still see?
- File names, sizes, which product they belong to, and who downloads what and when.
- Do my customers notice anything?
- No. Downloads work as before; the SDK decrypts them in memory.
End-to-end encryption · Files and folders · Product variables
Vaultix · Features · Pricing · Documentation · Changelog · llms.txt