About GCN.ONE
GCN.ONE is a zero-knowledge encrypted file-transfer service, operated by ORBCORE LTD - a company registered in England & Wales since 2012.
Files are encrypted on your device before they leave it. The key never reaches our servers, so what we hold is data we cannot read, and when the transfer window closes it is deleted. That is not a policy we promise to follow - it is a constraint the architecture imposes on us.
Company and operations
The details a procurement, security or compliance review tends to ask for first. Each one is set out formally on the pages linked below.
These are set out formally in our legal and company information, our Privacy Policy and our Terms and Conditions.
How the service is run
Where your data sits
Personal data and transfer metadata are stored on infrastructure inside the EU. We keep the number of sub-processors small, list them publicly, and bind each one by a processing agreement under GDPR Article 28; additions that could materially affect your rights are notified. Where a sub-processor sits outside the EU or UK, transfers rest on standard contractual clauses with transfer impact assessments - and because content is encrypted before it reaches us, ciphertext is all any of them could ever hold.
What happens during an incident
A personal-data breach triggers notification of affected users and the relevant supervisory authorities within 72 hours of us becoming aware, under GDPR Articles 33 and 34. Because file content is encrypted on the client with keys we never receive, a compromise of our servers or of a storage node exposes ciphertext rather than your files. Reports of misuse are acknowledged within 5 business days, and planned maintenance is announced where practicable.
What is committed in writing
A data processing agreement you can sign; a published sub-processor list with notice of changes; standard contractual clauses and transfer impact assessments for transfers to third countries; defined retention and deletion; the 72-hour breach notification above; and the support response times in our Terms. Availability is governed by those Terms rather than by a separate uptime guarantee, so if your procurement needs a formal service-level commitment, talk to us before you buy.
If you decide to leave
Files are downloaded and decrypted with keys you hold, either in the browser or through our SDK. There is no proprietary container and nothing on our side is needed to read them, so leaving - planned or not - does not put your data out of reach.
How it works, plainly
Every file you send through GCN.ONE is encrypted on your device before it leaves. The encryption key never touches our servers. We store encrypted data we cannot read, decrypt, or hand over in readable form. When the transfer window expires, the file is gone. No archive. No backup. No residual copy.
This isn't a privacy policy promise. It's how the system is built.
Privacy isn't a feature here. It's a constraint.
We made a deliberate architectural choice early on: the platform cannot offer certain things. No 'recover my file' requests. No admin access to content. No master key or recovery override.
These are not limitations. They are the product.
Built in Europe. Designed for Europe.
GCN.ONE was built to the GDPR standard from the start rather than retrofitted to it later. The company behind it is registered in the United Kingdom; the systems that hold your data run in the European Union. Processing therefore stays under EU data-protection law instead of depending on cross-border transfer arrangements, with UK GDPR applying alongside it.
Funding and independence
GCN.ONE is privately funded and ad-free: no advertising revenue, and no data brokerage on the side. Revenue comes from what customers pay for the service, which keeps the incentive on making the service worth paying for rather than on finding something else to do with your data. What we cannot read, we cannot sell.
Why we built it
Over the past two decades, cloud storage and file transfer have consolidated into the hands of a few very large providers.
That consolidation brought a pattern with it: services that are easy to enter and hard to leave, holding your data in systems you cannot inspect, on terms that can change without you.
On most services, a file you upload may be scanned, retained, restricted or made unavailable on terms you did not set. For holiday photos, that can be a reasonable trade. For a client file, a medical record or a deal document, it is not.
We built GCN.ONE because sending a confidential file should not mean handing over control of what is in it.
In practice that means deciding where files are stored, how they are protected, who can open them and when they are permanently deleted - and being able to show any of it to a regulator or a client.
It also means being able to leave without losing your data or your history.
So GCN.ONE was built as an alternative to lock-in: a file-transfer service where confidentiality is not a premium tier, security is not added afterwards, and your content and metadata are not for sale.
Software you can leave is software you can trust.