Secure Vaults: Zero-Knowledge Data Protection
In dewDrive, every backup destination is modeled as a Secure Vault. Data is chunked, compressed, and encrypted on your endpoint before it ever leaves your machine.
Cryptographic Guarantees
1. Client-Side Encryption
Master keys are derived via Argon2id / Scrypt key-derivation functions. All file payloads, metadata, directory trees, and chunk indexes are encrypted with AES-256-GCM or ChaCha20-Poly1305. Storage providers only see opaque, cryptographically random blobs.
2. Content-Defined Deduplication (CDC)
Using rolling Rabin-Karp hashes, files are split into variable-sized chunks. Only modified or brand-new chunks are transferred and stored, reducing storage consumption by up to 80% across repeated snapshot runs.
3. Immutable Snapshots & Ransomware Air-Gap
Snapshots form append-only Merkle tree graphs. Historical snapshots cannot be altered or retroactively corrupted by ransomware or rogue clients.
Universal Storage Targets
Attach any S3-compatible cloud target or local storage directory to create a Secure Vault:
Standard, Infrequent Access & Glacier
Zero egress fees & fast transfers
Low-cost cloud object storage
Direct filesystem, NFS, and SMB