Security & technical details

For IT and security consultants, risk teams and anyone who wants to check our claims

GCN.ONE is built around one constraint: the server must never see what you send unencrypted, or any key that could unlock it. Everything on this page follows from that single rule - stated precisely enough to be checked, including where the limits are.

What flows where
Browser
Generates the key, encrypts the file, holds the unencrypted version.
Server
Stores the encrypted data and a one-time random value. Never sees the key.
Recipient
Opens the link; the browser decrypts using the key from the link.
Ciphers and key wrapping

Your browser generates a random 256-bit key and encrypts every file using XSalsa20-Poly1305 via libsodium secretbox. The plaintext never leaves the browser. The server only ever sees ciphertext + nonce.

When the file is shared with another account holder, that key is wrapped to the recipient using a post-quantum hybrid construction - X25519 + ML-KEM-768 → HKDF → AES-256-GCM - so a future quantum adversary that records the wrapped key today still can't unwrap it.

Splitting the link from the key

You get two share options side by side: a full link with the unlock key included after the # symbol for one-click access, or a link plus a separate key for splitting the share across two channels - send the link by email and the key over Signal, SMS, or a phone call, so no single intercepted channel is enough to open the file.

Encrypted metadata

Subject, message, and every individual file name are encrypted on your device too. The server only ever sees scrambled storage chunks and random storage IDs - not the names, not the descriptions, not the contents.

Infrastructure and jurisdiction

GCN.ONE runs entirely on European infrastructure under EU jurisdiction, so your data stays under EU data-protection law rather than depending on cross-border transfer arrangements.

When a transfer expires, the encrypted data is permanently deleted - no archive, no backup, no residual copy. We collect what we need to prove delivery, and nothing more.

Frequently asked questions

No. Files, filenames, the subject and the message are all encrypted on your device before upload. The encryption key is never sent to our servers. We receive and store encrypted data we cannot read.

European infrastructure under EU jurisdiction - your data stays under EU data-protection law, not dependent on cross-border transfer arrangements.
The delivery record, the hash chain behind it and the public verification page are documented separately.