Cloud storage that’s actually private. Your files are locked on your device before they ever reach us. Only you hold the key. Not us, not anyone.
Free tier includes 2 GB encrypted storage · View all plans
Security first
Every layer of Sefaly is designed around one principle: your data is yours alone.
Every file is encrypted with AES-256-GCM in your browser before it ever touches a network. We literally cannot see your data.
File encryption keys are wrapped with ML-KEM (CRYSTALS-Kyber), the NIST post-quantum standard. Safe today and tomorrow.
Your private key is encrypted with a key derived in the browser from your password. Sign-in uses short-lived proofs instead of replayable login material.
Built on the Web Crypto API. No plugins, no extensions, no trust required in third-party binaries. Just open your browser.
How it works
From your device to our servers, your data is never exposed.
Pick any file from your device. It stays local until encryption is complete.
Drag & drop or click to browseA random 256-bit key is generated. Your file is encrypted with AES-256-GCM right in your browser.
crypto.subtle.encrypt()The file key is encapsulated using your ML-KEM public key. Only your private key can recover it.
NIST FIPS 203 compliantOnly encrypted bytes leave your machine. The server stores ciphertext it can never decrypt.
Zero-knowledge storageWhy quantum-safe?
Adversaries are harvesting encrypted data today, betting that future quantum computers will crack classical encryption. It’s called “harvest now, decrypt later.”
Sefaly uses ML-KEM (FIPS 203), the NIST-standardized post-quantum key encapsulation mechanism based on module lattices. It’s designed to resist both classical and quantum attacks.
Traditional encryption (RSA, ECDH)
Broken by Shor’s algorithm on a quantum computer
Sefaly’s ML-KEM (lattice-based)
No known quantum or classical attack. NIST standardized.
AES-256-GCM
Authenticated encryption with 256-bit keys
ML-KEM-768
Module-Lattice KEM (CRYSTALS-Kyber)
PBKDF2-SHA256
600,000 iterations for password-based keys
Argon2id
Memory-hard hashing, GPU/ASIC resistant
Create an account in seconds. No credit card. No tracking. Just encryption that’s built to last.