This blog is going to get technical — that is rather the point of it. But this first post is for the people who sign the contracts, not the people who review the code. No jargon from here on: what GCN.ONE actually does, what you would use it for, and the one question that separates it from every ordinary cloud service.
The short version
GCN.ONE moves and stores files. So does half the internet. The difference is a single design decision: your files are locked on your own computer before they travel, and no key that opens them ever exists on our side. Not in a database, not in a manager's drawer, not in an emergency procedure. We store sealed boxes and we rent out shelf space; what is inside them is structurally none of our business.
Every provider promises confidentiality. The question worth asking any of them — including us — is not “do you promise?” but “who holds the keys?” With most services, the honest answer is: they do. Their promise is a policy, enforced by rules and good behaviour. Ours is a structure: the key to your files never leaves your hands, so our rules and our behaviour do not need to be trusted.
We did not build a company you have to trust. We built a system where our trustworthiness is, for the most part, beside the point.
A bank that rents vaults but keeps no keys
The nearest everyday picture is a safe-deposit box — with one twist. A real bank keeps a second key. We do not. You lock the box before it enters the building, and what sits in our vault is the sealed box itself: we can count the boxes, weigh them, move them between rooms for safekeeping — and that is all anyone on our side can ever do with them.
Follow that through to the bad day. If someone breaks into an ordinary provider, they walk out with documents. If someone breaks into us, they walk out with sealed boxes and no keys. The same is true of a rogue employee, a buyer of the company, or anyone who shows up with legal paperwork: nobody can hand over what nobody holds.
| The question to ask | Ordinary cloud storage | GCN.ONE |
|---|---|---|
| Who can read your files? | You — and the provider, whose policy says they won’t | You, and the people you choose. No one else, including us |
| What does a breach of the provider expose? | Your documents | Sealed boxes, without keys |
| Forgot your password? | Reset it and carry on | Your files are gone — we hold nothing that opens them |
| The confidentiality rests on… | Policy and good behaviour | Structure: the keys never existed on our side |
Read the third row again, because it is not a flaw — it is the proof. Any service that can reset your forgotten password and give you your old files back is telling you, politely, that it holds a key to them. That test costs nothing and works on every vendor pitch you will ever sit through.
What you would actually use it for
Anything that today travels as an email attachment while making your compliance officer quietly unwell:
- Board papers, contracts, financial statements — documents whose leak has a price on it.
- Deals and audits — handing due-diligence files to lawyers, auditors or a counterparty without your documents sitting readable on somebody else's server.
- Payroll and HR files — personal data that regulation says you must protect, shared with exactly the people who need it.
- Files with a shelf life — transfers can be set to expire, so access ends on the date you choose instead of living forever in someone's inbox.
- The one-off send — no account, no installation: the front page of gcn.one sends a locked file in less time than it took to read this section.
The pattern behind all of these is the same. Email is a postcard, and most “secure” portals are a locked truck with a second key at the depot. GCN.ONE is the sealed box: nothing between your machine and your recipient's can be opened along the way — and if the worst happens on our side, the conversation starts with “they took sealed boxes,” not “they took our documents.”
The fine print, in the open
A pitch that lists no costs is hiding them, so here are ours:
- Your password is genuinely yours. Lose it and your stored files are gone; there is no recovery desk, because a recovery desk is a key in disguise. Treat the password the way you treat the only key to anything.
- We still see the shape, never the contents. We know how much you store, when it moves, and which accounts you share with. We cannot see what the files are, what they contain, or even what they are called — names are locked along with everything else.
- Your own computer is the one place plaintext exists. No storage service — ours included — can protect a machine that is itself compromised or a screen someone is reading over your shoulder.
Why believe any of this
Bold claims are cheap in this industry, which is why the rest of this blog exists. The posts that follow open the hood: what “zero-knowledge” means precisely and what it does not, the exact journey a file takes from your browser to storage, and the record-keeping we built so that edits to history — even ours — are detectable rather than merely forbidden. They are written for your technical people, and we would genuinely like your technical people to read them — systems like this deserve scrutiny, and scrutiny is the only compliment that counts.
If you want the machinery, start with what “zero-knowledge” actually means — and what it doesn’t. If you would rather just see it work, send a file — it takes a minute and no account.