Security

Built so you don't have to trust us with your files

Most clouds ask you to hand over everything and take their word for it. Mive is built the other way around: your files stay on your own disk, and we keep no copy of them — ever. To connect your devices we run a relay that passes the traffic through, but it stores nothing. Here's exactly how that works — and exactly what we keep.

We keep no copy of your files

Your files are never uploaded to us, copied, scanned, or stored — they live only on your own disk. To link your devices, Mive runs a relay that forwards the traffic between them. The data passes through it in transit, but the relay keeps none of it: no contents, no copies, nothing written to disk, not even for a moment.

Locked to the folders you choose — a contained guest on your PC

The part of Mive that's reachable over the network runs under its own restricted operating-system account that can only ever touch the folders you pick — each one fenced individually. It isn't a setting we promise to honour — your operating system enforces the boundary. A second, more privileged piece handles only the secure connection and never touches your files. It doesn't open up the rest of your machine, and it uninstalls cleanly — your files stay exactly where they are.

You decide who gets access — and what they can do with it

Nothing is shared until you say so. You share a file or a folder with one specific person, invited by their email address, as a Viewer — they can look and download — or an Editor, who can also add and change things. Or you open a link to everyone, no account needed: view-only, or a drop-off link if you want people to send you files. By default a link gives no one access — you're the one who turns it on. And any access can be taken back whenever you want, person by person.

Encrypted connections, no open doors

Your devices reach your PC through a private, encrypted tunnel built on WireGuard. The traffic is encrypted the whole way across the network. Mive forwards no router port and reaches the network through an outbound tunnel it dials itself — so no port on your computer is open to the public internet, and there's nothing for strangers online to find or knock on.

Signed, verified updates

Every update is cryptographically signed and checked on your own machine before it installs — and if anything looks wrong, it automatically rolls back. A tampered or partial update simply can't install.

What our servers handle — and what they never keep

Our servers handle

  • Your email and account, to sign you in
  • The names of the computers you connect
  • Who you've shared links with
  • A temporary private address so your devices can find each other

Our servers never keep

  • The contents of your files
  • The names and folder structure of your files
  • Any copy of a file — ever, even briefly
  • Analytics, trackers, or advertising IDs

See the exact list in our Privacy Policy.

Nothing to breach — and nothing to lose

If Mive were ever breached, there'd be nothing of yours to take: we keep no copy of your files, and store none. And if Mive disappeared tomorrow, every file would stay exactly where it always was — on your own disk. Close your account and we delete what little we hold — your email, your computer names, your share links; your files were never ours to delete, they're already yours.

Don't take our word for it

Mive is built and run by an independent developer — not a data company — and everything runs in the European Union (Germany), under EU privacy law. We'd rather you didn't take any of this on faith: we minimise what you have to trust us with — your files stay on your disk and we keep no copy — and we give you things you can check for yourself.

  • The installer is code-signed — your operating system shows a verified publisher before it runs.
  • A SHA-256 checksum is published with each release, so you can confirm your download is intact.
  • No open door to the internet — Mive forwards no router port; the one local service port it listens on is firewall-restricted to your private mesh and rejects anyone who isn't signed in.
  • A published security contact and policy at /.well-known/security.txt.
For the technically curious
  • The connection relay terminates TLS to route your traffic to the right PC, so it does handle your data in transit — but it streams it straight through and stores nothing: no disk writes, no caching, no logging of file contents.
  • The part that actually serves your files opens no public port and checks every request against your permissions. It runs as a locked-down OS account, fenced by file permissions to the folders you chose — it can't even read Mive's own network keys, which a separate, more privileged piece holds.
  • Connections use WireGuard — a protocol that has been independently audited and formally verified. (That audit and verification are WireGuard's own.)
  • Updates are signed with Ed25519 + SHA-256 and verified on-device before an atomic swap, behind a health gate with automatic rollback.
  • Your PC proves it's really yours with a short-lived certificate that's auto-renewed well before it expires. A machine that goes dark (lost, stolen, switched off for good) can't renew, so it drops out on its own.
  • On the private network, only Mive's relay can open a connection to your PC — no other machine on it can reach yours. Your PC's address there is temporary, auto-reclaimed within about half an hour if it goes offline.
  • Admin actions (changing your folders, resetting, promoting the first account) are reachable only from your own machine, on localhost — a web page can never trigger them.

Reporting a vulnerability

Found a security issue? We want to hear about it. Email [email protected] (full policy at /.well-known/security.txt). We'll acknowledge your report within 72 hours, and we won't pursue or support legal action against good-faith research that stays in scope. Please give us a reasonable window to ship a fix before public disclosure — we'll keep you updated throughout.

Your files, on your disk. Reachable anywhere.

Free forever. Two minutes to set up. Your files never leave your disk.

Already set up? Open your drive →