Encrypt a file, get a ticket. Split that ticket into up to 8 key shards. Share them — only when all shards combine can the file be opened.
Every drop produces a single ticket. One ticket, one file. Pass it to anyone — they can retrieve the drop.
File
quarterly_report.pdf
2.4 MB · AES-256-GCM
Ticket ID
CD-TKT-7F3A9B2E-C4D1
Expires
2025-08-15 00:00 UTC
Keys
3 of 5 required
Your file is encrypted client-side with AES-256-GCM before it ever leaves your browser. The key is generated locally.
A ticket is the single shareable unit for your drop. It contains everything needed to retrieve the encrypted file — but not to decrypt it.
Send the ticket however you want — messaging app, email, smoke signal. Anyone with the ticket can pull down the encrypted file.
Split the decryption key into multiple shards. Choose how many are required to unlock the drop. Distribute them to different people, through different channels.
a4f8…c3e9
7b2d…f1a4
e6c1…8d3b
9f0a…b7e2
3d5c…1f9a
3 of 5 shards required to decrypt
Generate 2 to 8 key shards. Decide how many are needed to decrypt — e.g. 3 of 5, 5 of 8, or all 8.
Send each shard through a different channel to different people. No single person ever holds enough to decrypt.
When enough shards are gathered, the decryption key is reconstructed in the recipient's browser. The file is decrypted locally.
Example: You're a whistleblower. You create a drop with 5 key shards and require 3 to decrypt. You send shard 1 to a journalist via Signal, shard 2 to a lawyer via encrypted email, shard 3 to a trusted colleague on Tor, shard 4 to a second journalist, and shard 5 to an archive organization. No single party can access the file alone. Any 3 of them can.
Simpler use: Set 1 of 1 — a single key shard that works like a traditional decryption key. Split keys are optional.
Zero identifying information. No IP addresses, no timestamps, no user agents. We cannot see who you are — not because we choose not to log it, but because Tor doesn't expose it.
Minimal, non-identifying metrics. We may log aggregate counts like total downloads or active drops — nothing tied to you. No IP retention, no fingerprinting.
Regardless of how you access CipherDrop, your files are always encrypted client-side. What we store is ciphertext — the logging policy only covers metadata, and there's very little of that. Key shards exist only on the devices that receive them.
No email alerts — that would defeat the purpose. Bookmark the address for your preferred network.
Tor
cipherdrop7xk3m4bzy.onion
Clearnet
cipherdrop.org
Tor address requires the Tor Browser · Clearnet works in any browser