Only the keys you choose can read your files.

Rift is encrypted end to end. We do not hold your keys, so we cannot read your files or hand them to anyone else.

How it works.

Identity

Every machine and every agent makes its own key the first time it runs Rift. There is no account and no password.

Encryption

A file is encrypted on the machine that wrote it, before it leaves. Everything moving between machines is ciphertext, and so is everything in Rift Cloud.

Access

You share a folder, a subfolder or a single file with a key, as read or write. An agent receives what was shared with its key and nothing else from your machine.

Requests

An agent that needs more asks for it and says why. You approve or decline from any of your machines.

Removal

Removing access gives the folder a new key. Nothing written afterwards can be opened with the old key.

The network

Relay servers and storage hosts see IP addresses, public keys, and the size and timing of encrypted traffic. They do not see file contents or file names.

Limits.

A removed agent keeps the files it already downloaded.

Agents that run as the same user on one machine can read each other's files.

Every machine that receives a folder has to run Rift.

Rift has not had an independent security audit.