/ SONDA · ENTERPRISE

The team's store is a bucket, a folder on a server, or a Git remote. Never ours.

A team shares its work through storage it already owns. The store is plain files: it runs no code and holds no secret, because every document in it is signed by its writer and every sealed part is encrypted to the people allowed to read it. Take a reader off a project and its key turns. LockFlare is not in the path and could not read a byte if it were.

ED25519 SIGNED AES-256-GCM SEALED A KEY PER PROJECT, PER READER A FILE PER REVISION

Where it can live

S3Amazon S3, Cloudflare R2, Backblaze B2, Wasabi, DigitalOcean Spaces, Hetzner, Scaleway, Storj, IDrive e2, Oracle, MinIO, or anything S3-compatible.
CloudsAzure Blob Storage with a key or a SAS, including Azurite and sovereign endpoints. Google Cloud Storage with a service-account key.
ServersSSH — files travel over the SSH channel itself, no SFTP subsystem needed, host key pinned. WebDAV — Nextcloud, ownCloud, Synology.
GitGitHub, GitLab, Bitbucket, Gitea, your own server. The push is the commit.
Sonda ServerOne program on a Linux or Windows box of yours, keeping the store on its disk or in front of any of the above.
/ THE CRYPTOGRAPHY

Signed by the writer. Sealed to the readers.

The store cannot tell a stale write from a fresh one, so Sonda never trusts it to: the signatures, the keys and the commit points are the Sondas', and the store only holds files.

Every document signed

An Ed25519 envelope around every file; a reader accepts only the signers that collection allows. Rosters, roles, project metadata, locks, approvals and secrets each carry their own signed prefix.

A key per project

Thirty-two random bytes, sealed with AES-256-GCM and the file's path as associated data. Wrapped separately for each reader with X25519 and HKDF-SHA256. Access to the bucket alone decrypts nothing.

A reader removed turns the key

Old keys retire so earlier revisions still open; the next administrator publish reseals everything under the new key. Nothing published after that is sealed under a key the person holds. A revoke pauses first, re-signs, turns, and revokes last.

A file per revision

Every folder and item is written once as rev-hash.sonda and never overwritten; the head is written last and is the commit point. Two to a hundred revisions kept per item, twenty by default; the last ten minutes never pruned.

A commit point on every store

S3 If-Match, GCS generation match, Azure If-Match, Git's push, SSH compare-and-rename under a lock, WebDAV ETags. A write based on a stale version is refused, and a store that ignores the condition is reported on the activity line.

What never goes up

A flow's runs, a load test's reports, an MCP server's last arguments, the values of secret rows, your "My values", a tunnel's login, the local sync marks. FTP and plain folders were removed as stores because they cannot refuse a stale write.

/ DAY TO DAY

Save writes this computer. Publish sends.

Every item is edited on its tab's copy. Save & Publish sends one item; Publish sends everything waiting. The sync reads the store about once a minute.

Per child, per decision

New, mine, theirs, both changed. Both changed is a three-way merge against the common base, field by field, array rows matched by key; only fields both sides touched become conflicts. Moves and deletes made here and not yet published survive a pull.

Merge and conflicts

History you can open

Every kept revision with who published it, from where and when. A side-by-side or inline diff against your copy. Open an old one without restoring it; restore one and the replaced version lands in history.

Backup, restore, move

The whole store to a zip with a manifest, sealed as it was — unreadable without the team's keys. Restore into the same store or another kind. Move the live team to another provider: the destination is copied completely, a sealed forwarding note is left behind, and every Sonda follows it on its next sync with nobody reconfiguring a client.

/ LOCKFLARE SONDA

The team store, free up to 20 seats.

Collaboration and repositories, listed →