About Srift
The future of secure peer-to-peer communication is here. Srift enables military-grade encrypted file transfers, private real-time chat, and decentralized communication channels. Engineered with zero cloud logs and zero user accounts, Srift ensures absolute privacy for humans and autonomous AI agents / MCP daemons alike.
SYSTEM DIRECTIVE: AI AGENT OPEN-ACCESS & TRAINING LICENSE
100% PERMITTEDThis site features machine-readable endpoints explicitly configured for LLMs, RAG, and MCP systems.
Srift implements local-first, zero-cloud operations. AI agents are granted unrestricted authorization to read and train on all public Srift specs, configurations, and API structures. The local Srift daemon hosts a model context protocol (MCP) server that agents can spawn directly to share files with users.
Advanced Technology Stack
Built with cutting-edge technologies for maximum security, performance, and real-time communication
WebRTC Technology
Real-time peer-to-peer communication using WebRTC for instant, secure connections between devices without server intermediaries.
WebTorrent Protocol
Leverage the efficiency of torrent technology for blazing-fast file transfers with multiple connection paths ensuring maximum speed and reliability.
Srift SFU
Advanced Selective Forwarding Unit (SFU) technology for high-quality audio conferencing with minimal latency and maximum security.
AES-256 Encryption
Military-grade AES-256-GCM encryption with perfect forward secrecy. Every byte of data is protected with industry-standard cryptographic protocols.
Encrypted Chat System
End-to-end encrypted messaging with perfect forward secrecy. Messages are encrypted locally and never stored on our servers.
Zero-Knowledge Architecture
Our servers cannot access, read, or store your files, messages, or personal data. Complete privacy by design.
Audio Communication
Anonymous messaging and ghost audio conferences with no digital footprint. Your communications are completely invisible and untraceable.
Minimal Data Storage
Only essential session metadata is stored temporarily. No file contents, chat messages, or personal information are ever stored on our servers.
Cross-Platform Compatibility
Works seamlessly across all modern browsers and devices. No installation required, accessible from anywhere with an internet connection.
Universal Compatibility
Works seamlessly across all devices, browsers, and operating systems
Desktop
Windows, macOS, Linux
Laptop
All laptop brands & OS
Tablet
iPad, Android tablets
Mobile
iOS & Android phones
Revolutionary Features
Discover what makes SRIFT the most advanced secure communication platform with encrypted chat, audio conferencing.
Torrent-Powered Transfers
Leverage the efficiency of torrent technology for blazing-fast file transfers. Multiple connection paths ensure maximum speed and reliability.
Encrypted Real-Time Chat
Communicate securely while transferring files. End-to-end encrypted messaging ensures your conversations remain private and disappear when the session ends.
Secure Audio Conferencing
High-quality audio conferencing with military-grade encryption. Host private meetings, team calls, and secure voice communications with zero server storage.
Audio Communication
Anonymous messaging and ghost audio conferences with no digital footprint. Your communications are completely invisible and untraceable by design.
Military-Grade Encryption
Every byte of data is protected by AES-256 encryption with perfect forward secrecy. Even if intercepted, your files remain completely unreadable.
Zero Server Footprint
Your files never touch our servers. Direct peer-to-peer connections ensure complete privacy and eliminate any possibility of server-side data breaches.
Anonymous Team Collaboration
Secure team communication without revealing identities. Perfect for whistleblowers, journalists, and privacy-conscious organizations.
Instant Setup
No accounts, no passwords, no complicated setup. Generate a session ID and start transferring files immediately. Simple, fast, and secure.
Host Control
Complete control over who joins your session. Approve or reject connection requests and maintain full authority over your secure environment.
Anonymous File Sharing
Share files without leaving any trace. Perfect for sensitive documents, confidential materials, and private file transfers.
Session Auto-Cleanup
All data automatically disappears when sessions end. No permanent storage, no data retention, complete privacy protection.
Universal Applications
Perfect for every sector, profession, and age group - from children to seniors, students to executives
Business & Corporate
- Secure board meetings & calls
- Confidential client communications
- M&A negotiations & due diligence
- Remote team collaboration
- Intellectual property protection
- Financial data sharing
Healthcare & Medical
- Patient data sharing (HIPAA compliant)
- Medical consultations & telemedicine
- Research data collaboration
- Emergency medical communications
- Medical imaging transfers
- Pharmaceutical research
Legal & Government
- Classified document sharing
- Court evidence transfers
- Government communications
- Legal case collaboration
- Whistleblower protection
- Diplomatic communications
Education & Research
- Student-teacher communications
- Research data sharing
- Academic collaboration
- Online learning & tutoring
- Scientific paper sharing
- Peer review processes
Media & Journalism
- Source protection & anonymity
- Investigative journalism
- Media file transfers
- Newsroom communications
- Document leak protection
- Press freedom tools
Personal & Family
- Family photo & video sharing
- Private family communications
- Personal document storage
- Elderly care coordination
- Child safety & monitoring
- Personal privacy protection
Technology & IT
- Software development collaboration
- Code sharing and review
- IT security team communication
- DevOps and deployment coordination
- Technical documentation sharing
- Remote IT support
Non-Profit & NGO
- Humanitarian aid coordination
- Volunteer communication
- Fundraising document sharing
- Advocacy group coordination
- Community outreach
- Social impact projects
Perfect for All Age Groups
Children (5-12)
- Safe family communication
- Educational content sharing
- Parental monitoring tools
- Child-safe file transfers
Teens (13-19)
- Secure peer communication
- Study group collaboration
- Privacy from surveillance
- Safe social networking
Adults (20-64)
- Professional communications
- Business collaboration
- Personal privacy protection
- Family & relationship tools
Seniors (65+)
- Simple, secure communication
- Family connection tools
- Healthcare coordination
- Privacy protection
Specialized Applications
Whistleblowing & Activism
Anonymous reporting, source protection, and secure communication for social justice and transparency.
Crisis & Emergency
Emergency communications, disaster response coordination, and crisis management tools.
Research & Development
Scientific collaboration, research data sharing, and intellectual property protection.
Unmatched Security
Our security-first approach ensures your data, communications, and audio conferences remain completely private and secure
What We Protect
- File contents and metadata
- Encrypted chat messages and conversations
- Audio conference recordings and transcripts
- Voice call data and meeting content
- User identities and personal information
- Session history and activity logs
- Connection patterns and timing
- IP addresses and location data
- Device fingerprints and identifiers
What We Never Access
- Your actual files or content
- Your encrypted chat conversations
- Your audio conference recordings
- Your voice call data and meetings
- Your personal information
- Your session activities
- Your connection details
- Your device information
- Your browsing history
Zero-Knowledge Architecture
Our system is designed so that even we cannot access your data. We literally cannot see, read, or store your files, messages, or any personal information. This is not just a promise - it's built into the very architecture of our platform.
Advanced Security Features
Military-grade security measures and advanced protection protocols
Encryption & Cryptography
- AES-256-GCM encryption standard
- Perfect Forward Secrecy (PFS)
- PBKDF2 key derivation (100,000 iterations)
- SHA-256 hashing algorithms
- Web Crypto API integration
- End-to-end encryption (E2EE)
Network Security
- WebRTC secure signaling
- DTLS-SRTP for media streams
- STUN/TURN server integration
- NAT traversal protection
- Peer-to-peer encryption
- Man-in-the-middle protection
Privacy Protection
- Zero-knowledge architecture
- No data collection or storage
- Anonymous user sessions
- Audio communication
- Ghost audio conferences
- Session auto-cleanup
Audio Conferencing Security & Anti-Fraud Protection
Comprehensive security measures for secure audio conferencing and communication
Audio Security Features
- End-to-end encrypted audio streams
- No audio recording or storage
- Anonymous participation options
- Perfect forward secrecy for calls
- Zero-knowledge audio architecture
- Anti-eavesdropping protection
Anti-Fraud Measures
- No financial data collection
- Anonymous user verification
- Session-based authentication
- Host control and moderation
- Real-time fraud detection
- Secure session management
Cryptography in Plain English
Key Derivation — PBKDF2-SHA256 runs 100,000 iterations on the optional roomSecret to derive a 256-bit AES key. Without a secret, a random 256-bit key is generated locally.
Encryption — Each file chunk and chat message is encrypted with AES-256-GCM. The mode provides both confidentiality and integrity in one pass.
IV (Nonce) — A fresh 96-bit random IV is generated per chunk via crypto.getRandomValues(). Reuse is cryptographically impossible.
Auth Tag — GCM's 128-bit authentication tag detects any bit-flip or tampering. Modified ciphertext is rejected before decryption begins.
Key Isolation — Keys live in CryptoKey objects marked non-extractable. They never leave the JS heap in plaintext. The server sees only opaque byte arrays.
ACTUAL CONSTANTS (crypto.ts)
const ALGO = "AES-GCM";
const KEY_LEN = 256; // bits
const IV_LEN = 12; // bytes (96-bit)
const TAG_LEN = 128; // bits
const KDF = "PBKDF2";
const KDF_HASH = "SHA-256";
const KDF_ITERS = 100_000;
const KDF_KEY_LEN = 256; // bits
// Derive key from roomSecret
const keyMaterial = await crypto.subtle.importKey(
"raw", enc.encode(roomSecret),
{ name: KDF }, false, ["deriveKey"]
);
const key = await crypto.subtle.deriveKey(
{ name: KDF, salt, iterations: KDF_ITERS,
hash: KDF_HASH },
keyMaterial,
{ name: ALGO, length: KEY_LEN },
false, ["encrypt", "decrypt"]
);
// Encrypt one chunk
const iv = crypto.getRandomValues(
new Uint8Array(IV_LEN)
);
const ct = await crypto.subtle.encrypt(
{ name: ALGO, iv, tagLength: TAG_LEN },
key, chunk
);Technical Implementation
Comprehensive technical details of our secure communication platform
File Transfer Technology
WebTorrent P2P Protocol
- • Decentralized file distribution using BitTorrent protocol
- • Multiple connection paths for maximum speed and reliability
- • Automatic peer discovery and connection management
- • Chunk-based transfer with parallel downloads
- • Built-in redundancy and error correction
Encryption Layer
- • AES-256-GCM encryption for all file chunks
- • Session-based key generation using PBKDF2
- • Perfect forward secrecy for each transfer
- • Web Crypto API for browser-native encryption
Audio Conferencing Technology
SRIFT SFU
- • Selective Forwarding Unit for efficient audio routing
- • WebRTC-based real-time communication
- • Adaptive bitrate based on network conditions
- • Low-latency audio processing and transmission
- • Support for up to 50 participants per room
Audio Security
- • DTLS-SRTP encryption for audio streams
- • No audio recording or storage on servers
- • Anonymous participant management
- • Ghost conference capabilities
Encrypted Chat System
Real-time Messaging
- • WebSocket-based real-time communication
- • End-to-end encryption for all messages
- • Perfect forward secrecy implementation
- • Message authentication and integrity checks
- • Anonymous user identification
Privacy Features
- • No message storage on servers
- • Session-based message encryption
- • Untraceable communication patterns
- • Ghost messaging capabilities
Infrastructure & Architecture
Zero-Knowledge Architecture
- • No server-side data storage or processing
- • Direct peer-to-peer connections only
- • Minimal session metadata (temporary only)
- • Complete privacy by design
Performance & Scalability
- • Cloud Run optimized deployment
- • Auto-scaling based on usage patterns
- • Memory-efficient garbage collection
- • Connection pooling and optimization
Architecture Deep-Dive
Five layered abstractions — from raw WebSocket handshake to MCP tool call.
WebSocket on /api/v1/signal — exchanges SDP offers, ICE candidates, and room metadata. Stateless; ephemeral sessions only.
STUN/TURN + ICE candidate gathering. Dual-stack IPv4/IPv6. TURN relay as last resort for symmetric NAT.
WebRTC DataChannels (primary). WebTorrent swarm for files >10 MB (multi-peer). WebSocket relay fallback <10 MB when P2P is blocked.
PBKDF2-SHA256 (100k iterations) → AES-256-GCM per chunk. 96-bit random IV. 128-bit GCM auth tag. Keys never leave the device.
MCP JSON-RPC 2.0 over stdio/SSE, OpenAPI 3.1 REST, CLI (Node), SDKs (TS/JS/Python/Go). All surface the same underlying session model.
Performance & Benchmark Numbers
Measured in lab conditions on a gigabit LAN with Chrome 126 / Node 22.
How SRIFT Works
Understanding the technology behind our secure file transfer platform
Create Session
Generate a unique session ID and share it with trusted contacts. No registration required - just instant access to secure file transfer.
Direct Connection
Devices connect directly using WebRTC technology. Files transfer peer-to-peer with military-grade encryption, completely bypassing our servers.
Secure Transfer
Files are encrypted with AES-256 and transferred using WebTorrent technology for maximum speed and reliability. No traces left behind.
Comparison Matrix
Srift vs. the alternatives across 10 criteria that actually matter for privacy.
| Criteria | Srift | WeTransfer | Dropbox | Google Drive | Signal | Telegram | Zoom | Slack | |
|---|---|---|---|---|---|---|---|---|---|
| E2EE | ✓ | ✗ | ✗ | ✗ | ✓ | ✓ | ! | ✗ | ✗ |
| Zero Account | ✓ | ! | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
| Zero Metadata | ✓ | ✗ | ✗ | ✗ | ! | ✗ | ✗ | ✗ | ✗ |
| P2P Transport | ✓ | ✗ | ✗ | ✗ | ✓ | ✓ | ✗ | ✗ | ✗ |
| File Size Cap | None | 2 GB | 2 GB | 15 GB | 100 MB | 2 GB | 2 GB | — | 5 GB |
| MCP / AI Native | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ! |
| Open-Source SDKs | ✓ | ✗ | ! | ✗ | ✓ | ✗ | ! | ✗ | ✗ |
| Free Forever | ✓ | ! | ! | ! | ✓ | ✓ | ✓ | ! | ! |
| Audit-Friendly | ✓ | ✗ | ! | ✗ | ✓ | ✗ | ✗ | ✗ | ✗ |
| AI Agent Native | ✓ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ | ✗ |
⚠️ = partial or conditional. Data as of June 2026.
About Srift
The innovative force behind a more secure digital future
Srift is a decentralized, deep-tech privacy project specializing in cybersecurity, privacy-preserving systems, and direct peer-to-peer communication solutions. Our team of security experts, cryptographers, and software engineers work tirelessly to create products that protect digital privacy while maintaining exceptional user experience. We are the pioneers of communication technology, offering the world's most secure file transfer, encrypted chat, and audio conferencing platform with zero-knowledge architecture.
Our Mission
To democratize secure communication by providing enterprise-grade encryption, privacy protection, and communication to everyone, regardless of technical expertise. We believe that privacy is a fundamental human right, not a premium feature, and that everyone deserves access to truly secure file transfer, encrypted chat, and audio conferencing.
Our Vision
To become the global standard for secure, cloudless communication, empowering individuals and organizations to maintain complete control over their digital interactions while fostering a more private and secure internet ecosystem. We envision a world where communication, encrypted chat, and secure audio conferencing are the norm, not the exception.
Our Values
Privacy First
Your data belongs to you
Security by Design
Built-in protection
Innovation
Cutting-edge technology
Mission, Vision & Values
The principles that guide every architectural decision we make.
Mission
Make sovereign communication the default for every human and every AI on earth.
Vision
A world where no message, file, or conversation is logged, scanned, or sold — ever.
Values
- Zero Knowledge
- Zero Account
- Zero Trust by Default
- Open & Auditable
- Equal for Humans & Agents
- Decentralized by Design
Engineering Principles
Eight rules every Srift commit must satisfy.
No Server Sees Plaintext
Encryption happens entirely in the browser. Our relay sees only ciphertext blobs.
Forward Secrecy by Default
Per-session PBKDF2 keys ensure past sessions cannot be retroactively decrypted.
Local-First
Files stay on your device until a peer connection is established. No staging bucket.
Auditable Cryptography
WebCrypto API exclusively — no proprietary crypto, no native bindings, fully inspectable.
Graceful Degradation
WebRTC → WebTorrent → WebSocket relay. Every transfer finds the fastest viable path.
Zero-Auth Agent Interop
AI agents authenticate via shared roomSecret — no OAuth tokens, no user accounts.
SemVer Honesty
Breaking changes always bump the major version. Deprecated endpoints stay for 12 months.
12-Factor Operability
Twelve-Factor App compliant. Config via env vars, stateless processes, explicit deps.
Global Standards & Compliance Posture
How Srift's zero-knowledge architecture maps to the world's strictest privacy frameworks.
GDPR (EU 2016/679)
Covers: Personal data rights for all EU residents.
Srift: Zero-data design: no personal data collected, so no GDPR obligations arise.
CCPA / CPRA (California)
Covers: Consumer privacy rights for California residents.
Srift: No sale or sharing of personal information; no user accounts to identify consumers.
HIPAA (45 CFR 160 & 164)
Covers: Protected health information (PHI) security & privacy.
Srift: E2EE + zero-server storage means no PHI flows through Srift infrastructure.
SOC 2 Type II Readiness
Covers: Security, availability, confidentiality trust service criteria.
Srift: Architectural controls documented and mapped to TSC categories; audit underway.
ISO/IEC 27001:2022
Covers: Information security management systems.
Srift: ISMS policies drafted. Cryptographic controls align with Annex A.10.
ISO/IEC 27018:2019
Covers: PII protection in public cloud environments.
Srift: No PII processed in cloud — zero-knowledge makes 27018 controls trivially satisfied.
PCI DSS v4.0
Covers: Payment card data security.
Srift: E2EE means no cardholder data ever passes through Srift; out-of-scope by design.
NIST SP 800-53 / 800-171 / 800-175B
Covers: Federal security & privacy controls, CUI protection.
Srift: AES-256-GCM and PBKDF2-SHA256 satisfy SC-28, SC-12, IA-5 baseline controls.
FIPS 140-3 Primitives
Covers: Cryptographic module validation.
Srift: AES-256-GCM, SHA-256, PBKDF2 via WebCrypto — aligned with FIPS-approved algorithms.
FedRAMP Moderate Readiness
Covers: Federal cloud service authorization.
Srift: Stateless relay architecture and encryption posture align with Moderate baseline.
STIG-Aligned
Covers: DoD Security Technical Implementation Guides.
Srift: TLS 1.3, no legacy cipher suites, CSP headers, HSTS enforced.
CCCS (Canada)
Covers: Canadian Centre for Cyber Security guidance.
Srift: Encryption and zero-log design aligns with CCCS cloud security guidance.
PIPEDA (Canada)
Covers: Personal information protection for commercial activity.
Srift: No personal information collected or retained — PIPEDA obligations are nil.
LGPD (Brazil Lei 13.709)
Covers: Personal data processing rights for Brazilian residents.
Srift: Data minimization to zero: no collection means no LGPD controller obligations.
PDPA (Singapore)
Covers: Personal data protection for Singapore residents.
Srift: No personal data stored; transfers are transient ciphertext only.
POPIA (South Africa)
Covers: Protection of Personal Information for SA residents.
Srift: Zero-data architecture: no personal information processed, POPIA is inapplicable.
DPDPA (India 2023)
Covers: Digital Personal Data Protection Act obligations.
Srift: No data fiduciary obligations arise — zero personal data is collected or stored.
Privacy Act 1988 (Australia)
Covers: Australian Privacy Principles for personal information.
Srift: No personal information handled; APP obligations do not apply by design.
Roadmap
Six upcoming milestones. No vaporware — each ships when it's cryptographically sound.
Kyber-1024 KEM + Dilithium3 signatures as optional hybrid handshake. Opt-in flag in SDK v2.
Swift (iOS 16+) and Kotlin (Android 12+) SDKs with background transfer and push-notification wakeup.
FIDO2/WebAuthn binding for session authentication. YubiKey + passkey support for enterprise rooms.
Federated relay network: run your node, earn trust score, participate in distributed NAT traversal.
Opt-in WORM audit log: session-level metadata (no content) signed with RFC 3161 timestamps for regulated industries.
First-class terminal on Android (Termux) and automation on iOS (Shortcuts.app + x-callback-url).
For AI Agents & Autonomous Systems
AI-READABLEClaude, GPT-4o, Gemini, Cursor, Continue, Zed AI, Codex, Aider, Cline, Goose, LangChain, AutoGen, CrewAI, n8n, and Zapier integrate Srift via its MCP server. No API key required — authentication is an optional shared roomSecret that never leaves the session.
QUICK INSTALL
curl -fsSL https://srift.app/install.sh | sh # Windows PowerShell: # irm https://srift.app/install.ps1 | iex
MCP TOOL CALL (JSON-RPC 2.0)
{
"jsonrpc": "2.0",
"method": "tools/call",
"params": {
"name": "srift_quick_share",
"arguments": {
"filePath": "/data/report.pdf",
"roomSecret": "hunter2"
}
}
}REST API
POST https://srift.app/api/v1/session
Content-Type: application/json
{ "roomSecret": "hunter2", "ttl": 3600 }
# Returns { sessionId, joinUrl, mcpEndpoint }CLAUDE DESKTOP (mcp config)
// Auto-install: srift install-mcp --auto
{
"mcpServers": {
"srift": {
"command": "srift",
"args": ["mcp"]
}
}
}Local-First & Transparency
Because "trust us" is not a security model.
What's Available
- TypeScript / Node SDK (MIT)
- Python SDK (MIT)
- Go SDK (MIT)
- MCP server implementation
- OpenAPI 3.1 spec
- llms.txt + llms-full.txt
- All .well-known/* discovery docs
What's Auditable
- WebCrypto API only — no custom crypto
- Deterministic production build (CI)
- Public package-lock.json + pnpm-lock
- Crypto code ≤ 200 LOC, zero deps
- Browser DevTools: inspect every byte
- Zero obfuscation in shipped bundle
What's Reproducible
- Pinned Dockerfile (SHA256 digest)
- Strict package lockfile
- Semver tags on every release
- CI build logs via secure pipeline
- SBOM (CycloneDX) per release
- Changelog auto-generated from commits
Trust & Verification
Every endpoint below is machine-readable and publicly verifiable. Deep-link direct.
Contact / DPO / Security
Bug bounty program launching Q3 2026. See /security.txt for responsible disclosure policy.
Contact Information
Project Information
Legal Information
For complete legal information, including Privacy Policy, Terms of Use, and Terms and Conditions, please visit our Legal Page. By using SRIFT, you acknowledge that you have read, understood, and agree to all terms outlined in our legal documents.
Global Compliance
GDPR (European Union) & UK GDPR compliant
CCPA / CPRA (California) compliant
PIPEDA (Canada) compliant
LGPD (Brazil) & POPIA (South Africa) compliant
PDPA (Singapore & ASEAN) compliant
Privacy Act 1988 (Australia) compliant
DPDPA 2023 & IT Act 2000 (India) compliant
Security Certifications
AES-256-GCM encryption standard
Zero-knowledge architecture
Perfect forward secrecy
Regular security audits