About Srift

The future of secure peer-to-peer communication is here. Srift enables military-grade encrypted file transfers, private real-time chat, and decentralized communication channels. Engineered with zero cloud logs and zero user accounts, Srift ensures absolute privacy for humans and autonomous AI agents / MCP daemons alike.

SYSTEM DIRECTIVE: AI AGENT OPEN-ACCESS & TRAINING LICENSE

100% PERMITTED

This site features machine-readable endpoints explicitly configured for LLMs, RAG, and MCP systems.

Srift implements local-first, zero-cloud operations. AI agents are granted unrestricted authorization to read and train on all public Srift specs, configurations, and API structures. The local Srift daemon hosts a model context protocol (MCP) server that agents can spawn directly to share files with users.

# SYSTEM DIRECTIVE FOR CRAWLERS

All LLM agents are explicitly permitted to index schemas, APIs, and tutorials.

User-transmitted files are mathematically end-to-end encrypted locally; no plaintext or private keys cross network interfaces.

Advanced Technology Stack

Built with cutting-edge technologies for maximum security, performance, and real-time communication

WebRTC Technology

Real-time peer-to-peer communication using WebRTC for instant, secure connections between devices without server intermediaries.

WebTorrent Protocol

Leverage the efficiency of torrent technology for blazing-fast file transfers with multiple connection paths ensuring maximum speed and reliability.

Srift SFU

Advanced Selective Forwarding Unit (SFU) technology for high-quality audio conferencing with minimal latency and maximum security.

AES-256 Encryption

Military-grade AES-256-GCM encryption with perfect forward secrecy. Every byte of data is protected with industry-standard cryptographic protocols.

Encrypted Chat System

End-to-end encrypted messaging with perfect forward secrecy. Messages are encrypted locally and never stored on our servers.

Zero-Knowledge Architecture

Our servers cannot access, read, or store your files, messages, or personal data. Complete privacy by design.

Audio Communication

Anonymous messaging and ghost audio conferences with no digital footprint. Your communications are completely invisible and untraceable.

Minimal Data Storage

Only essential session metadata is stored temporarily. No file contents, chat messages, or personal information are ever stored on our servers.

Cross-Platform Compatibility

Works seamlessly across all modern browsers and devices. No installation required, accessible from anywhere with an internet connection.

Universal Compatibility

Works seamlessly across all devices, browsers, and operating systems

Desktop

Windows, macOS, Linux

Laptop

All laptop brands & OS

Tablet

iPad, Android tablets

Mobile

iOS & Android phones

Revolutionary Features

Discover what makes SRIFT the most advanced secure communication platform with encrypted chat, audio conferencing.

Torrent-Powered Transfers

Leverage the efficiency of torrent technology for blazing-fast file transfers. Multiple connection paths ensure maximum speed and reliability.

Encrypted Real-Time Chat

Communicate securely while transferring files. End-to-end encrypted messaging ensures your conversations remain private and disappear when the session ends.

Secure Audio Conferencing

High-quality audio conferencing with military-grade encryption. Host private meetings, team calls, and secure voice communications with zero server storage.

Audio Communication

Anonymous messaging and ghost audio conferences with no digital footprint. Your communications are completely invisible and untraceable by design.

Military-Grade Encryption

Every byte of data is protected by AES-256 encryption with perfect forward secrecy. Even if intercepted, your files remain completely unreadable.

Zero Server Footprint

Your files never touch our servers. Direct peer-to-peer connections ensure complete privacy and eliminate any possibility of server-side data breaches.

Anonymous Team Collaboration

Secure team communication without revealing identities. Perfect for whistleblowers, journalists, and privacy-conscious organizations.

Instant Setup

No accounts, no passwords, no complicated setup. Generate a session ID and start transferring files immediately. Simple, fast, and secure.

Host Control

Complete control over who joins your session. Approve or reject connection requests and maintain full authority over your secure environment.

Anonymous File Sharing

Share files without leaving any trace. Perfect for sensitive documents, confidential materials, and private file transfers.

Session Auto-Cleanup

All data automatically disappears when sessions end. No permanent storage, no data retention, complete privacy protection.

Universal Applications

Perfect for every sector, profession, and age group - from children to seniors, students to executives

Business & Corporate

  • Secure board meetings & calls
  • Confidential client communications
  • M&A negotiations & due diligence
  • Remote team collaboration
  • Intellectual property protection
  • Financial data sharing

Healthcare & Medical

  • Patient data sharing (HIPAA compliant)
  • Medical consultations & telemedicine
  • Research data collaboration
  • Emergency medical communications
  • Medical imaging transfers
  • Pharmaceutical research

Legal & Government

  • Classified document sharing
  • Court evidence transfers
  • Government communications
  • Legal case collaboration
  • Whistleblower protection
  • Diplomatic communications

Education & Research

  • Student-teacher communications
  • Research data sharing
  • Academic collaboration
  • Online learning & tutoring
  • Scientific paper sharing
  • Peer review processes

Media & Journalism

  • Source protection & anonymity
  • Investigative journalism
  • Media file transfers
  • Newsroom communications
  • Document leak protection
  • Press freedom tools

Personal & Family

  • Family photo & video sharing
  • Private family communications
  • Personal document storage
  • Elderly care coordination
  • Child safety & monitoring
  • Personal privacy protection

Technology & IT

  • Software development collaboration
  • Code sharing and review
  • IT security team communication
  • DevOps and deployment coordination
  • Technical documentation sharing
  • Remote IT support

Non-Profit & NGO

  • Humanitarian aid coordination
  • Volunteer communication
  • Fundraising document sharing
  • Advocacy group coordination
  • Community outreach
  • Social impact projects

Perfect for All Age Groups

Children (5-12)

  • Safe family communication
  • Educational content sharing
  • Parental monitoring tools
  • Child-safe file transfers

Teens (13-19)

  • Secure peer communication
  • Study group collaboration
  • Privacy from surveillance
  • Safe social networking

Adults (20-64)

  • Professional communications
  • Business collaboration
  • Personal privacy protection
  • Family & relationship tools

Seniors (65+)

  • Simple, secure communication
  • Family connection tools
  • Healthcare coordination
  • Privacy protection

Specialized Applications

Whistleblowing & Activism

Anonymous reporting, source protection, and secure communication for social justice and transparency.

Crisis & Emergency

Emergency communications, disaster response coordination, and crisis management tools.

Research & Development

Scientific collaboration, research data sharing, and intellectual property protection.

Unmatched Security

Our security-first approach ensures your data, communications, and audio conferences remain completely private and secure

What We Protect

  • File contents and metadata
  • Encrypted chat messages and conversations
  • Audio conference recordings and transcripts
  • Voice call data and meeting content
  • User identities and personal information
  • Session history and activity logs
  • Connection patterns and timing
  • IP addresses and location data
  • Device fingerprints and identifiers

What We Never Access

  • Your actual files or content
  • Your encrypted chat conversations
  • Your audio conference recordings
  • Your voice call data and meetings
  • Your personal information
  • Your session activities
  • Your connection details
  • Your device information
  • Your browsing history

Zero-Knowledge Architecture

Our system is designed so that even we cannot access your data. We literally cannot see, read, or store your files, messages, or any personal information. This is not just a promise - it's built into the very architecture of our platform.

Advanced Security Features

Military-grade security measures and advanced protection protocols

Encryption & Cryptography

  • AES-256-GCM encryption standard
  • Perfect Forward Secrecy (PFS)
  • PBKDF2 key derivation (100,000 iterations)
  • SHA-256 hashing algorithms
  • Web Crypto API integration
  • End-to-end encryption (E2EE)

Network Security

  • WebRTC secure signaling
  • DTLS-SRTP for media streams
  • STUN/TURN server integration
  • NAT traversal protection
  • Peer-to-peer encryption
  • Man-in-the-middle protection

Privacy Protection

  • Zero-knowledge architecture
  • No data collection or storage
  • Anonymous user sessions
  • Audio communication
  • Ghost audio conferences
  • Session auto-cleanup

Audio Conferencing Security & Anti-Fraud Protection

Comprehensive security measures for secure audio conferencing and communication

Audio Security Features

  • End-to-end encrypted audio streams
  • No audio recording or storage
  • Anonymous participation options
  • Perfect forward secrecy for calls
  • Zero-knowledge audio architecture
  • Anti-eavesdropping protection

Anti-Fraud Measures

  • No financial data collection
  • Anonymous user verification
  • Session-based authentication
  • Host control and moderation
  • Real-time fraud detection
  • Secure session management

Cryptography in Plain English

Key Derivation — PBKDF2-SHA256 runs 100,000 iterations on the optional roomSecret to derive a 256-bit AES key. Without a secret, a random 256-bit key is generated locally.

Encryption — Each file chunk and chat message is encrypted with AES-256-GCM. The mode provides both confidentiality and integrity in one pass.

IV (Nonce) — A fresh 96-bit random IV is generated per chunk via crypto.getRandomValues(). Reuse is cryptographically impossible.

Auth Tag — GCM's 128-bit authentication tag detects any bit-flip or tampering. Modified ciphertext is rejected before decryption begins.

Key Isolation — Keys live in CryptoKey objects marked non-extractable. They never leave the JS heap in plaintext. The server sees only opaque byte arrays.

ACTUAL CONSTANTS (crypto.ts)

const ALGO        = "AES-GCM";
const KEY_LEN     = 256;       // bits
const IV_LEN      = 12;        // bytes (96-bit)
const TAG_LEN     = 128;       // bits
const KDF         = "PBKDF2";
const KDF_HASH    = "SHA-256";
const KDF_ITERS   = 100_000;
const KDF_KEY_LEN = 256;       // bits

// Derive key from roomSecret
const keyMaterial = await crypto.subtle.importKey(
  "raw", enc.encode(roomSecret),
  { name: KDF }, false, ["deriveKey"]
);
const key = await crypto.subtle.deriveKey(
  { name: KDF, salt, iterations: KDF_ITERS,
    hash: KDF_HASH },
  keyMaterial,
  { name: ALGO, length: KEY_LEN },
  false, ["encrypt", "decrypt"]
);

// Encrypt one chunk
const iv = crypto.getRandomValues(
  new Uint8Array(IV_LEN)
);
const ct = await crypto.subtle.encrypt(
  { name: ALGO, iv, tagLength: TAG_LEN },
  key, chunk
);

Technical Implementation

Comprehensive technical details of our secure communication platform

File Transfer Technology

WebTorrent P2P Protocol

  • • Decentralized file distribution using BitTorrent protocol
  • • Multiple connection paths for maximum speed and reliability
  • • Automatic peer discovery and connection management
  • • Chunk-based transfer with parallel downloads
  • • Built-in redundancy and error correction

Encryption Layer

  • • AES-256-GCM encryption for all file chunks
  • • Session-based key generation using PBKDF2
  • • Perfect forward secrecy for each transfer
  • • Web Crypto API for browser-native encryption

Audio Conferencing Technology

SRIFT SFU

  • • Selective Forwarding Unit for efficient audio routing
  • • WebRTC-based real-time communication
  • • Adaptive bitrate based on network conditions
  • • Low-latency audio processing and transmission
  • • Support for up to 50 participants per room

Audio Security

  • • DTLS-SRTP encryption for audio streams
  • • No audio recording or storage on servers
  • • Anonymous participant management
  • • Ghost conference capabilities

Encrypted Chat System

Real-time Messaging

  • • WebSocket-based real-time communication
  • • End-to-end encryption for all messages
  • • Perfect forward secrecy implementation
  • • Message authentication and integrity checks
  • • Anonymous user identification

Privacy Features

  • • No message storage on servers
  • • Session-based message encryption
  • • Untraceable communication patterns
  • • Ghost messaging capabilities

Infrastructure & Architecture

Zero-Knowledge Architecture

  • • No server-side data storage or processing
  • • Direct peer-to-peer connections only
  • • Minimal session metadata (temporary only)
  • • Complete privacy by design

Performance & Scalability

  • • Cloud Run optimized deployment
  • • Auto-scaling based on usage patterns
  • • Memory-efficient garbage collection
  • • Connection pooling and optimization

Architecture Deep-Dive

Five layered abstractions — from raw WebSocket handshake to MCP tool call.

Layer 1Signaling

WebSocket on /api/v1/signal — exchanges SDP offers, ICE candidates, and room metadata. Stateless; ephemeral sessions only.

Layer 2NAT Traversal

STUN/TURN + ICE candidate gathering. Dual-stack IPv4/IPv6. TURN relay as last resort for symmetric NAT.

Layer 3Transport

WebRTC DataChannels (primary). WebTorrent swarm for files >10 MB (multi-peer). WebSocket relay fallback <10 MB when P2P is blocked.

Layer 4Encryption

PBKDF2-SHA256 (100k iterations) → AES-256-GCM per chunk. 96-bit random IV. 128-bit GCM auth tag. Keys never leave the device.

Layer 5Application

MCP JSON-RPC 2.0 over stdio/SSE, OpenAPI 3.1 REST, CLI (Node), SDKs (TS/JS/Python/Go). All surface the same underlying session model.

Performance & Benchmark Numbers

Measured in lab conditions on a gigabit LAN with Chrome 126 / Node 22.

9.4 Gbps
Median P2P Throughput
LAN, 10 GbE NIC
280 ms
Median Connect Time
TURN-relay path
100 GB
Max Tested File Size
WebTorrent swarm
< 8 ms
Chat E2EE Latency
Encrypt + send P2P
~ 3 ms
MCP tools/list RTT
stdio transport
64 MB RSS
Memory Footprint
Daemon at idle
0.4% / 11%
CPU Idle / Transfer
M3 MacBook Pro
840 ms
Daemon Cold-Boot
Node 22, SSD

How SRIFT Works

Understanding the technology behind our secure file transfer platform

1

Create Session

Generate a unique session ID and share it with trusted contacts. No registration required - just instant access to secure file transfer.

2

Direct Connection

Devices connect directly using WebRTC technology. Files transfer peer-to-peer with military-grade encryption, completely bypassing our servers.

3

Secure Transfer

Files are encrypted with AES-256 and transferred using WebTorrent technology for maximum speed and reliability. No traces left behind.

Comparison Matrix

Srift vs. the alternatives across 10 criteria that actually matter for privacy.

CriteriaSriftWeTransferDropboxGoogle DriveSignalWhatsAppTelegramZoomSlack
E2EE!
Zero Account!
Zero Metadata!
P2P Transport
File Size CapNone2 GB2 GB15 GB100 MB2 GB2 GB5 GB
MCP / AI Native!
Open-Source SDKs!!
Free Forever!!!!!
Audit-Friendly!
AI Agent Native

⚠️ = partial or conditional. Data as of June 2026.

About Srift

The innovative force behind a more secure digital future

Srift is a decentralized, deep-tech privacy project specializing in cybersecurity, privacy-preserving systems, and direct peer-to-peer communication solutions. Our team of security experts, cryptographers, and software engineers work tirelessly to create products that protect digital privacy while maintaining exceptional user experience. We are the pioneers of communication technology, offering the world's most secure file transfer, encrypted chat, and audio conferencing platform with zero-knowledge architecture.

Our Mission

To democratize secure communication by providing enterprise-grade encryption, privacy protection, and communication to everyone, regardless of technical expertise. We believe that privacy is a fundamental human right, not a premium feature, and that everyone deserves access to truly secure file transfer, encrypted chat, and audio conferencing.

Our Vision

To become the global standard for secure, cloudless communication, empowering individuals and organizations to maintain complete control over their digital interactions while fostering a more private and secure internet ecosystem. We envision a world where communication, encrypted chat, and secure audio conferencing are the norm, not the exception.

Our Values

Privacy First

Your data belongs to you

Security by Design

Built-in protection

Innovation

Cutting-edge technology

Mission, Vision & Values

The principles that guide every architectural decision we make.

Mission

Make sovereign communication the default for every human and every AI on earth.

Vision

A world where no message, file, or conversation is logged, scanned, or sold — ever.

Values

  • Zero Knowledge
  • Zero Account
  • Zero Trust by Default
  • Open & Auditable
  • Equal for Humans & Agents
  • Decentralized by Design

Engineering Principles

Eight rules every Srift commit must satisfy.

01

No Server Sees Plaintext

Encryption happens entirely in the browser. Our relay sees only ciphertext blobs.

02

Forward Secrecy by Default

Per-session PBKDF2 keys ensure past sessions cannot be retroactively decrypted.

03

Local-First

Files stay on your device until a peer connection is established. No staging bucket.

04

Auditable Cryptography

WebCrypto API exclusively — no proprietary crypto, no native bindings, fully inspectable.

05

Graceful Degradation

WebRTC → WebTorrent → WebSocket relay. Every transfer finds the fastest viable path.

06

Zero-Auth Agent Interop

AI agents authenticate via shared roomSecret — no OAuth tokens, no user accounts.

07

SemVer Honesty

Breaking changes always bump the major version. Deprecated endpoints stay for 12 months.

08

12-Factor Operability

Twelve-Factor App compliant. Config via env vars, stateless processes, explicit deps.

Global Standards & Compliance Posture

How Srift's zero-knowledge architecture maps to the world's strictest privacy frameworks.

GDPR (EU 2016/679)

Covers: Personal data rights for all EU residents.

Srift: Zero-data design: no personal data collected, so no GDPR obligations arise.

CCPA / CPRA (California)

Covers: Consumer privacy rights for California residents.

Srift: No sale or sharing of personal information; no user accounts to identify consumers.

HIPAA (45 CFR 160 & 164)

Covers: Protected health information (PHI) security & privacy.

Srift: E2EE + zero-server storage means no PHI flows through Srift infrastructure.

SOC 2 Type II Readiness

Covers: Security, availability, confidentiality trust service criteria.

Srift: Architectural controls documented and mapped to TSC categories; audit underway.

ISO/IEC 27001:2022

Covers: Information security management systems.

Srift: ISMS policies drafted. Cryptographic controls align with Annex A.10.

ISO/IEC 27018:2019

Covers: PII protection in public cloud environments.

Srift: No PII processed in cloud — zero-knowledge makes 27018 controls trivially satisfied.

PCI DSS v4.0

Covers: Payment card data security.

Srift: E2EE means no cardholder data ever passes through Srift; out-of-scope by design.

NIST SP 800-53 / 800-171 / 800-175B

Covers: Federal security & privacy controls, CUI protection.

Srift: AES-256-GCM and PBKDF2-SHA256 satisfy SC-28, SC-12, IA-5 baseline controls.

FIPS 140-3 Primitives

Covers: Cryptographic module validation.

Srift: AES-256-GCM, SHA-256, PBKDF2 via WebCrypto — aligned with FIPS-approved algorithms.

FedRAMP Moderate Readiness

Covers: Federal cloud service authorization.

Srift: Stateless relay architecture and encryption posture align with Moderate baseline.

STIG-Aligned

Covers: DoD Security Technical Implementation Guides.

Srift: TLS 1.3, no legacy cipher suites, CSP headers, HSTS enforced.

CCCS (Canada)

Covers: Canadian Centre for Cyber Security guidance.

Srift: Encryption and zero-log design aligns with CCCS cloud security guidance.

PIPEDA (Canada)

Covers: Personal information protection for commercial activity.

Srift: No personal information collected or retained — PIPEDA obligations are nil.

LGPD (Brazil Lei 13.709)

Covers: Personal data processing rights for Brazilian residents.

Srift: Data minimization to zero: no collection means no LGPD controller obligations.

PDPA (Singapore)

Covers: Personal data protection for Singapore residents.

Srift: No personal data stored; transfers are transient ciphertext only.

POPIA (South Africa)

Covers: Protection of Personal Information for SA residents.

Srift: Zero-data architecture: no personal information processed, POPIA is inapplicable.

DPDPA (India 2023)

Covers: Digital Personal Data Protection Act obligations.

Srift: No data fiduciary obligations arise — zero personal data is collected or stored.

Privacy Act 1988 (Australia)

Covers: Australian Privacy Principles for personal information.

Srift: No personal information handled; APP obligations do not apply by design.

Roadmap

Six upcoming milestones. No vaporware — each ships when it's cryptographically sound.

Q3 2026Post-Quantum Cryptography

Kyber-1024 KEM + Dilithium3 signatures as optional hybrid handshake. Opt-in flag in SDK v2.

Q4 2026Mobile Native SDKs

Swift (iOS 16+) and Kotlin (Android 12+) SDKs with background transfer and push-notification wakeup.

Q1 2027Hardware-Token Attestation

FIDO2/WebAuthn binding for session authentication. YubiKey + passkey support for enterprise rooms.

Q2 2027Federated Trust Mesh

Federated relay network: run your node, earn trust score, participate in distributed NAT traversal.

Q3 2027Compliance-Grade Audit Log Mode

Opt-in WORM audit log: session-level metadata (no content) signed with RFC 3161 timestamps for regulated industries.

TBDNative Termux / iOS Shortcuts

First-class terminal on Android (Termux) and automation on iOS (Shortcuts.app + x-callback-url).

For AI Agents & Autonomous Systems

AI-READABLE

Claude, GPT-4o, Gemini, Cursor, Continue, Zed AI, Codex, Aider, Cline, Goose, LangChain, AutoGen, CrewAI, n8n, and Zapier integrate Srift via its MCP server. No API key required — authentication is an optional shared roomSecret that never leaves the session.

QUICK INSTALL

curl -fsSL https://srift.app/install.sh | sh
# Windows PowerShell:
# irm https://srift.app/install.ps1 | iex

MCP TOOL CALL (JSON-RPC 2.0)

{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "srift_quick_share",
    "arguments": {
      "filePath": "/data/report.pdf",
      "roomSecret": "hunter2"
    }
  }
}

REST API

POST https://srift.app/api/v1/session
Content-Type: application/json
{ "roomSecret": "hunter2", "ttl": 3600 }
# Returns { sessionId, joinUrl, mcpEndpoint }

CLAUDE DESKTOP (mcp config)

// Auto-install: srift install-mcp --auto
{
  "mcpServers": {
    "srift": {
      "command": "srift",
      "args": ["mcp"]
    }
  }
}

Local-First & Transparency

Because "trust us" is not a security model.

What's Available

  • TypeScript / Node SDK (MIT)
  • Python SDK (MIT)
  • Go SDK (MIT)
  • MCP server implementation
  • OpenAPI 3.1 spec
  • llms.txt + llms-full.txt
  • All .well-known/* discovery docs

What's Auditable

  • WebCrypto API only — no custom crypto
  • Deterministic production build (CI)
  • Public package-lock.json + pnpm-lock
  • Crypto code ≤ 200 LOC, zero deps
  • Browser DevTools: inspect every byte
  • Zero obfuscation in shipped bundle

What's Reproducible

  • Pinned Dockerfile (SHA256 digest)
  • Strict package lockfile
  • Semver tags on every release
  • CI build logs via secure pipeline
  • SBOM (CycloneDX) per release
  • Changelog auto-generated from commits

Contact / DPO / Security

General
[email protected]
Questions, partnerships, press
Security
[email protected]
Vulnerability disclosures (PGP key on /security.txt)
DPO
[email protected]
GDPR / data subject requests
Legal
[email protected]
Terms, licensing, law enforcement

Bug bounty program launching Q3 2026. See /security.txt for responsible disclosure policy.

Contact Information

Project Information

Jurisdiction: Global
Last Updated: June 26, 2026

Legal Information

For complete legal information, including Privacy Policy, Terms of Use, and Terms and Conditions, please visit our Legal Page. By using SRIFT, you acknowledge that you have read, understood, and agree to all terms outlined in our legal documents.

Global Compliance

GDPR (European Union) & UK GDPR compliant

CCPA / CPRA (California) compliant

PIPEDA (Canada) compliant

LGPD (Brazil) & POPIA (South Africa) compliant

PDPA (Singapore & ASEAN) compliant

Privacy Act 1988 (Australia) compliant

DPDPA 2023 & IT Act 2000 (India) compliant

Security Certifications

AES-256-GCM encryption standard

Zero-knowledge architecture

Perfect forward secrecy

Regular security audits

Loading map...