The team's store is a bucket, a folder on a server, or a Git remote. Never ours.
A team shares its work through storage it already owns. The store is plain files: it runs no code and holds no secret, because every document in it is signed by its writer and every sealed part is encrypted to the people allowed to read it. Take a reader off a project and its key turns. LockFlare is not in the path and could not read a byte if it were.
Where it can live
Signed by the writer. Sealed to the readers.
The store cannot tell a stale write from a fresh one, so Sonda never trusts it to: the signatures, the keys and the commit points are the Sondas', and the store only holds files.
Every document signed
An Ed25519 envelope around every file; a reader accepts only the signers that collection allows. Rosters, roles, project metadata, locks, approvals and secrets each carry their own signed prefix.
A key per project
Thirty-two random bytes, sealed with AES-256-GCM and the file's path as associated data. Wrapped separately for each reader with X25519 and HKDF-SHA256. Access to the bucket alone decrypts nothing.
A reader removed turns the key
Old keys retire so earlier revisions still open; the next administrator publish reseals everything under the new key. Nothing published after that is sealed under a key the person holds. A revoke pauses first, re-signs, turns, and revokes last.
A file per revision
Every folder and item is written once as rev-hash.sonda and never overwritten; the head is written last and is the commit point. Two to a hundred revisions kept per item, twenty by default; the last ten minutes never pruned.
A commit point on every store
S3 If-Match, GCS generation match, Azure If-Match, Git's push, SSH compare-and-rename under a lock, WebDAV ETags. A write based on a stale version is refused, and a store that ignores the condition is reported on the activity line.
What never goes up
A flow's runs, a load test's reports, an MCP server's last arguments, the values of secret rows, your "My values", a tunnel's login, the local sync marks. FTP and plain folders were removed as stores because they cannot refuse a stale write.
Save writes this computer. Publish sends.
Every item is edited on its tab's copy. Save & Publish sends one item; Publish sends everything waiting. The sync reads the store about once a minute.
Per child, per decision
New, mine, theirs, both changed. Both changed is a three-way merge against the common base, field by field, array rows matched by key; only fields both sides touched become conflicts. Moves and deletes made here and not yet published survive a pull.
Merge and conflictsHistory you can open
Every kept revision with who published it, from where and when. A side-by-side or inline diff against your copy. Open an old one without restoring it; restore one and the replaced version lands in history.
Backup, restore, move
The whole store to a zip with a manifest, sealed as it was — unreadable without the team's keys. Restore into the same store or another kind. Move the live team to another provider: the destination is copied completely, a sealed forwarding note is left behind, and every Sonda follows it on its next sync with nobody reconfiguring a client.