Skip to content
VaultLiveBy request

Storage where trusting us is not part of the threat model

End-to-end encrypted file storage where plaintext never touches the server. Encrypted manifests and policy-based access by design.

How it works

What it does

Built for the files you cannot afford to leak

Encrypted File Sharing

Share files with end-to-end encryption so only authorized recipients can read the content.

Send a due-diligence pack to outside counsel without it sitting readable in anyone's inbox or drive.

Private Data Snapshots

Protect sensitive snapshots and collaborate on intermediate research outputs with controlled visibility.

Circulate an unpublished cohort dataset to three collaborators while the paper is still under review.

Encrypted Remote Repositories

Encrypt and share remote repositories while preserving traceability and confidentiality across teams.

Keep a security-sensitive codebase mirrored off-site without handing the source to whoever hosts it.

Synced Local Directories

Sync local encrypted directories across devices without exposing plaintext in transit or at rest.

Start an analysis on the office workstation, finish it on a laptop, and never leave a readable copy in between.

Hosted App Access Control

Apply fine-grained access control for hosted web applications with policy-based permissions.

Give a contractor access to one project for the length of an engagement, and take it back in a click.

How it works

Three steps, and the key never leaves you

The guarantee is a property of the design rather than a promise about our staff.

  1. It is locked where you are

    Your files are encrypted on your own device, before anything is sent. The passphrase that unlocks them is yours, and it does not travel with the file.

  2. Only the scrambled copy travels

    What reaches our servers and our storage is unreadable. File names, folder structure and file types are scrambled along with the contents, so even the shape of your work stays private.

  3. It opens only where you choose

    Unlocking happens back on a device you trust. You decide who holds a key — only you, named teammates, your whole team, or anyone with a link.

Being straight about it

What Vault does not do

The same design that keeps us out keeps us from helping in a few places. Those are here rather than in the small print.

  • If your own device is compromised, encryption cannot save what is open on it.
  • If a passphrase is stolen or shared carelessly, whoever holds it can read the project.
  • Lose the only copy of a passphrase and the files are unrecoverable — by you, and by us.

Who it is for

Teams where a leak is not recoverable

Research Labs & Investigators

  • Private Data Snapshots
  • Synced Local Directories
  • Encrypted File Sharing

Engineering & Development Teams

  • Encrypted Remote Repositories
  • Hosted App Access Control
  • Synced Local Directories

Operations & Governance Teams

  • Encrypted File Sharing
  • Hosted App Access Control

Questions

The things people ask first

Can anyone at Neurasense read my files?

No. Files are encrypted before they leave your device, and we never receive the key. What we hold is unreadable to us, and that is a property of the design rather than a promise about our staff.

What happens if I lose my passphrase?

The project cannot be opened again. There is no reset link and no back door for us to use on your behalf — the same reason nobody else can open your files. Keep passphrases in a password manager, and use a policy that shares the key with your team so one person is never the single point of failure.

What can you still see?

Account and billing details, that a project exists, and the ordinary operational facts of storage — roughly how much is held, and when it changed. Not the contents, not the file names, not the folder structure.

Does it slow the team down?

Locking and unlocking happen on your own device, in the background, while you work. The place people notice Vault is the moment of choosing who gets a key, which is the decision you wanted to make consciously anyway.

Can we host it ourselves?

Talk to us. Vault is already built so that the storage it runs against holds nothing readable, which makes the deployment conversation a short one.

How do we get started?

Request access below. We will set up your first project with you, help you pick a sharing policy that matches the sensitivity of the work, and share the design documentation your security team will want to read.

Tell us what you need to keep private

Vault is granted rather than signed up for. Say what you are storing and who needs to open it, and we will tell you whether it fits.