What is Rift?

Rift is an end-to-end encrypted filesystem that you share one folder at a time. You share a folder with a machine's public key, and that machine receives that folder and nothing else.

A coding agent in a cloud sandbox needs one folder of your work. Today you give it a git token, an SSH key or the login to a synced drive, and each of those opens more than the one folder the agent needed.

A coworker's laptop, a deploy machine, and a second agent that reviews the first all have the same need.

Permissions are local to one machine

Agent tools add allow rules, deny rules and prompts before an edit. The agent's own harness enforces them for one session on one machine. The rules cover files the agent can already reach, and none of them controls which files are sent to that machine.

Sharing controls what syncs

rift share project-a coder gives the coder write access to one folder, and that folder starts syncing to the coder's machine. Every machine has its own key. Your laptop and your desktop each have a key, and a folder shared with you reaches both.

A machine receives only the folders shared with it. The reviewer below can read the project and cannot change it. Every other machine rejects any change the reviewer signs.

Two agents share one project. The coder can edit it. The reviewer can only read it.

A deploy machine that was given website/dist cannot leak your source, because your source was never sent to it.

$ rift share project-a coder$ rift share project-a reviewer --read$ rift share website/dist deploy --read

Share across companies

A key is tied to no company's login, so the same command works across companies. Your agent and a client's agent can work in one folder without either side creating accounts on the other's systems.

A contractor gets team/docs for the length of the contract and nothing else in team. On the last day you run rift unshare, and every machine the contractor used loses access.

Transfer and Rift Cloud

Files move directly between machines, encrypted end to end. Connect Rift Cloud and every file is also stored there, so a folder stays available when the other machine is offline. It holds only ciphertext.

What removing access does

After rift unshare, the removed member cannot read anything new in the folder from any of their machines. The remaining machines reject every change those machines send.

After access is removed, the reviewer receives nothing new. What it already downloaded stays on its disk.

Removing access does not erase files a machine already downloaded. A machine that has a file can keep a copy of it. Replace any secret that was in a folder you removed access to.

Install Rift, or read the six jobs of file sync.