12 repository-uri
Systems that ensure data is encrypted on the sender's device and only decrypted by the intended recipient.
Explore 12 awesome GitHub repositories matching security & cryptography · End-To-End Encryption Systems. Refine with filters or upvote what's useful.
Joplin is an open-source, cross-platform note-taking application designed for secure, private knowledge management. It functions as a local-first productivity platform, maintaining a complete relational database on the user's device to ensure offline availability and high-performance data retrieval. The application prioritizes data sovereignty by implementing an end-to-end encryption layer, which secures all information locally with a master key before any synchronization occurs. The platform distinguishes itself through a delta-based synchronization engine that transmits only specific file c
Propagates master encryption keys across synchronized devices to maintain end-to-end security for all stored content.
Croc is a command-line utility for sending files and folders between computers using end-to-end encrypted peer-to-peer connections. It employs elliptic curve encryption and key agreement to secure data transmission between remote endpoints. The tool allows users to coordinate transfers using a shared code phrase and supports the operation of custom relay servers to facilitate connections without relying on public infrastructure. It also includes a proxy client to route encrypted traffic through SOCKS5 proxies. Additional capabilities include resumable data transmission for unstable connectio
Implements a system where data is encrypted on the sender's device and only decrypted by the intended recipient.
Deskreen is a wireless screen mirroring and virtual display tool that streams a computer screen or specific application windows to any device with a web browser. It functions as a virtual display streamer and a web-based secondary monitor, allowing users to extend their desktop workspace to remote devices over a local network. The system supports end-to-end encrypted screen sharing to protect display data and utilizes virtual display adapters to treat remote browsers as extended screens. It includes capabilities for multi-device broadcasting, enabling a single video source to be mirrored acro
Protects computer display data using end-to-end encryption for secure remote viewing on trusted devices.
Linsa.io is an end-to-end encrypted cloud storage service and zero-knowledge data vault. It functions as a private content sharing platform that encrypts files and data on the client side, ensuring only the owner can access the stored content. The project employs a local-first approach, processing data updates and encryption on the local device before syncing encrypted blobs to a remote persistence layer. It uses a zero-knowledge architecture where the service provider cannot access decryption keys or view the plaintext content of stored files. The platform provides capabilities for private
Ensures that shared private files are encrypted on the sender's device and only decrypted by authorized recipients.
Send is a self-hosted file transfer service designed for end-to-end encrypted file sharing. It provides a privacy-focused data transfer solution and ephemeral file storage where uploaded content is automatically deleted after a specified number of downloads or a set amount of time. The service ensures private file sharing by utilizing client-side encryption to protect data before it is uploaded. Decryption keys are distributed to recipients via URL hash fragments to ensure the server never has access to the keys. The platform supports encrypted data transfer and temporary file hosting. It us
Implements an end-to-end encrypted system where data is encrypted on the sender's device and decrypted only by the recipient.
This project is a comprehensive zero-knowledge security suite designed for enterprise credential management, secrets orchestration, and password management. It provides a secure, end-to-end encrypted vault that allows users to store, synchronize, and manage sensitive information, including passwords, passkeys, and infrastructure secrets, across desktop, mobile, and browser environments. The platform distinguishes itself through a strict zero-knowledge architecture where all encryption and decryption occur locally on the client, ensuring that plaintext data remains inaccessible to the server.
Ensures no service provider can access stored vault contents by using zero-knowledge architecture where only the user holds the keys.
Aegis is a mobile application designed to manage and store multi-factor authentication tokens. It functions as a local-first credential vault that generates time-based and counter-based one-time passwords to verify user identity across various online services. The application secures sensitive authentication data by employing authenticated symmetric encryption and hardware-backed key storage to protect credentials at rest. Access to the stored tokens is gated by system-level biometric authentication or password verification, ensuring that only authorized users can retrieve the generated secur
Facilitates secure cross-device recovery by synchronizing encrypted data blobs to remote storage providers.
CryptPad is a self-hosted, zero-knowledge office suite designed for real-time collaborative editing and content management. It provides a privacy-centric infrastructure where documents, files, and notes are encrypted in the browser before transmission, ensuring that the server administrator cannot access the underlying data. The platform implements zero-knowledge user authentication, utilizing cryptographic keys to verify identities so that plain text passwords are never stored on the server. To further isolate sensitive operations, the system employs a security architecture that separates th
Provides a real-time synchronization system for shared files using end-to-end encryption to keep content private from administrators.
Upspin is a decentralized naming and storage system that provides an end-to-end encrypted file system. It assigns every user a unique identity and organizes files within a global, permissioned namespace where data is encrypted on the client before transmission. The system separates identity resolution from data storage using a public-key identity provider and a key-server architecture. This allows for decentralized identity management and the resolution of usernames to specific directory and storage server addresses. The project includes a hierarchical access control system that manages read
Implements an end-to-end encrypted storage system where only authorized users can decrypt content.
Send is an end-to-end encrypted file sharing service that encrypts files on the sender's device before upload, ensuring the server never sees plaintext content. It generates secure download links that are designed for single use, automatically removing access after the first successful download, and associates each share with a time-limited access token that expires after a set duration. The service operates without requiring user accounts, lowering friction for ephemeral sharing, and uses cryptographic key derivation to generate decryption keys from the download URL, eliminating server-side
Shares files securely by encrypting them on the sender's device before transfer, ensuring only the intended recipient can decrypt and access them.
Ockam este un framework de rețea zero-trust conceput pentru a securiza tranzitul datelor între aplicații distribuite folosind un overlay de rețea bazat pe identitate. Oferă primitivele necesare pentru a stabili conexiuni autentificate reciproc și criptate end-to-end, eliminând dependența de securitatea tradițională la nivel de rețea. Proiectul se distinge prin utilizarea controlului accesului bazat pe atribute și a acreditărilor verificabile pentru a gestiona încrederea la scară. Implementează rotația identității criptografice pentru a menține continuitatea identității și se integrează cu sisteme de gestionare a cheilor bazate pe hardware pentru a securiza cheile private în enclave sau servicii de gestionare a cheilor în cloud. Platforma acoperă o gamă largă de capabilități, inclusiv rutarea binară multi-hop și bridging-ul de rețea bazat pe relee pentru a conecta rețele disparate. Poate împacheta traficul legacy TCP sau Kafka în tuneluri securizate, permițând serviciilor private să comunice fără a expune porturi de ascultare. În plus, utilizează un model de actor cu stare pentru a procesa mesajele asincron pe noduri distribuite. Implementarea este susținută prin template-uri de infrastructură ca cod pentru provizionarea nodurilor și gateway-urilor securizate în medii cloud.
Ensures data is encrypted on the sender's device and only decrypted by the intended recipient across distributed endpoints.
Microbin este o aplicație de partajare de fișiere self-hosted și un pastebin criptat scris în Rust. Oferă o platformă pentru găzduirea de snippet-uri de text și fișiere binare prin link-uri unice, funcționând atât ca un file drop securizat, cât și ca un URL shortener. Sistemul dispune de criptare end-to-end pe partea clientului, asigurându-se că serverul nu vede datele în clar înainte ca acestea să fie transmise. Include portaluri securizate de tip postbox pentru colectarea documentelor de la clienți externi și suportă controlul accesului protejat prin parolă pentru a restricționa vizibilitatea conținutului. Platforma gestionează ciclul de viață al încărcării prin timere de expirare bazate pe timp și vizualizări. Capabilitățile suplimentare includ evidențierea sintaxei specifice limbajului pentru snippet-urile de cod, editarea conținutului partajat și posibilitatea de a servi fișierele ca fluxuri de date brute. Comportamentul serverului și branding-ul aplicației sunt gestionate prin variabile de mediu și un instrument de generare a fișierelor de configurare.
Ensures data privacy by encrypting uploads on the client side so only authorized users can decrypt them.