Encrypted storage.
Controlled access.

Obris Vault is free to use with an active Obris VPN connection. Files are encrypted on the authorised device before upload, and Vault operates only through the Obris VPN network. It does not operate through another VPN provider or a normal internet connection.

FREE WITH OBRIS VPN Obris VPN required

The server is designed to store and move encrypted content without needing plaintext file contents or plaintext file encryption keys during normal operation.

Managed storage for individuals. Private deployment for organisations.

The Obris Vault app is free with an active Obris VPN connection, and Managed Vault includes a free starter storage tier. Larger managed storage options and Private or Enterprise deployments are separate offerings.

FREE STARTER

Vault Starter

Free

5 GB managed encrypted storage.

  • 5 GB storage quota
  • Client-side encrypted files
  • Encrypted folders and sharing
  • Managed Obris service
  • Obris VPN required for managed access
Open Google Play
LARGEST PLAN

Obris Vault 100 GB

100 GB

Higher capacity encrypted storage for larger Vault collections.

  • 100 GB storage quota
  • Encrypted upload and download
  • Folders and secure sharing
  • Trusted device authentication
  • Subscription managed through Google Play
Open Google Play
PRIVATE VAULT

A$499 / year

Customer-hosted single-node Vault for organisations that want to operate their own service.

Included users
10
Additional user
A$49 / user / year
Maximum nodes
1
Platform
Ubuntu 24.04 LTS x86_64
Contact Obris

Private and Enterprise values are the current configured catalogue defaults. One unique active Vault user account consumes one licence seat; linked devices for the same user do not consume additional seats.

Encrypted files, folders and sharing without giving the server a universal decryption key.

Vault keeps the user workflow familiar while moving file encryption and key ownership to authorised endpoints.

01

Encrypted upload and download

File content is encrypted locally before upload and decrypted locally after an authorised download.

02

Encrypted sharing

Recipients receive encrypted file-key envelopes rather than a decrypted server-side copy of the file.

03

Folders and subfolders

Encrypted folder metadata, viewer/editor sharing and inherited folder relationships are supported.

04

Trusted device authentication

New Vault installations use the existing Obris trusted-device approval path and proof of the device signing key.

05

Managed or Private Vault

Use the Obris managed service or configure an HTTPS customer-hosted Private Vault deployment.

06

Server-side quota enforcement

Reservations prevent concurrent uploads from silently exceeding the account storage limit.

Plaintext stays on the authorised endpoint.

The managed service performs authentication, storage, sharing relationships and quota enforcement on encrypted material. Obris VPN is the required network path for Vault access.

01Android clientEncrypts file content and holds private Vault keys.
02Obris VPNRequired protected network path for Vault.
03Vault APIEnforces auth, object lifecycle, sharing and quota rules.
04Encrypted storageStores ciphertext, encrypted manifests and key envelopes.

Be precise about what the server can and cannot see.

Zero knowledge content design does not mean zero metadata. Vault intentionally separates encrypted file content from the operational metadata needed to run the service.

SERVER CAN HOLD
  • Ciphertext object bytes
  • Encrypted manifests
  • Encrypted file-key envelopes
  • User public keys
  • Sharing relationships, quota, timestamps and audit metadata
SERVER SHOULD NOT REQUIRE
  • Plaintext document or photo contents
  • Plaintext file encryption keys
  • User private encryption/signing keys
  • A universal master key for every customer file

Managed, Private and Enterprise Vault.

The Android client defaults to Obris Managed Vault and can also select an HTTPS Private Vault endpoint. Obris VPN remains required for Vault client access.

Managed Vault

Hosted and operated by Obris. Obris manages the service, TLS, database, object storage, updates and consumer entitlement enforcement.

Private Vault

Customer-hosted single-node deployment with current version 1 support targeted at Ubuntu Server 24.04 LTS on x86_64.

Enterprise Vault

Uses the same encrypted content architecture with a larger included user count and additional node allowance.

Core Vault functions are implemented, with launch-readiness work still open.

Encrypted upload/download/delete, encrypted sharing, folders, VPN-only managed API access, trusted-device authentication and quota accounting are implemented. The supplied technical documentation also identifies multi-device key recovery, authoritative Google Play verification, off-server encrypted backups, monitoring and independent review as outstanding or planned readiness work.