Product objectives
- Enable senders to transfer large files (up to several GB)
- Ensure end-to-end encryption (E2EE) until the recipient's terminal
- Offer the recipient a sovereign option: maintain confidentiality (stay encrypted) or decrypt locally (final use)
- Eliminate any risk of server compromise or centralized key
Technical mechanism
Reference: Cryptographic specifications — Section 26 (K_file_v2)
| Element | Description |
|---|---|
| Encryption type | AES-256-GCM (authenticated encryption) |
| Key derivation | PBKDF2-HMAC-SHA256 (K_file_base) + HKDF_SHA256 (K_file_v2) from userId and K_seg |
| Transport | HTTPS + WebSocket / WebRTC depending on configuration |
| Session key | Local, volatile, not exchanged (deterministic derivation on peer sides) |
| Temporary storage | Encrypted file in database or on disk — never in plaintext |
| Recipient choice | Local decryption on demand, without server contact |
| Re-sharing | Possible only if file kept encrypted |
Strategic differentiator
CryptPeer®: the first sovereign system to offer "cryptographic choice upon receipt". To our knowledge, no competitor (BlueFiles, Tresorit, Proton, Kiteworks) currently allows a non-administrator end recipient to choose between encrypted or decrypted download in an E2EE communication context without a trusted third party.
Competitive comparison — File transfer
| Solution | Type | Encrypted/decrypted choice | Sovereignty | Indicative price (€/user/year) |
|---|---|---|---|---|
| BlueFiles | Professional SaaS (ANSSI) | ❌ | Service-side keys | ~12,500 €/user/yr (8-user pack ~100,000 €/yr) |
| Tresorit / Tresorit Send | Private SaaS | ❌ | Zero knowledge | ~240 €/user/yr |
| Proton Drive | Open-source SaaS | ❌ | Zero knowledge | ~120 €/user/yr |
| Internxt Send | Privacy-first SaaS | ❌ | Zero knowledge | Free |
| Kiteworks / GoAnywhere | Enterprise MFT | ❌ | Server keys | 30,000 €+ /yr (license, quote-based) |
| CryptPeer® Standard | Sovereign system | ✅ | Exclusive licensee control | 180 €/user/yr (Core) — 450 €/yr (Total) |
Sources: bluefiles.com — tresorit.com — proton.me — internxt.com — goanywhere.com — kiteworks.com. Indicative prices, quote-based depending on configuration.
Doctrinal positioning
CryptPeer® — The only sovereign communication and file transfer system enabling the end user to decide whether to maintain or lift encryption.
- No third-party cryptographic authority — no trusted server, no shared key
- Complete licensee sovereignty — transfer integrated with CryptPeer messaging
- Dual-Use defensive compliance — civil, institutional or defence
- Structural cost efficiency — no recurring hosting or per-user license costs
Key arguments
- End-to-end encryption without third party
- Sovereign choice of reception mode
- Self-hosted, auditable system
- GDPR and Dual-Use defensive compliant
- Economically rational vs managed SaaS
See also the full CryptPeer® vs competitors comparison and cryptographic specifications.
Full comparison → Why CryptPeer® →