Zero-knowledge sync for developers

Every file.Only yours.

Encrypted file and folder sync that keeps filenames, contents, and keys invisible to the server.

AQT / SYNCLOCAL FIRST
$aqt sync ~/vault

The storage provider is no longer a trusted party.

aqt encrypts locally with XChaCha20-Poly1305. Your root key never leaves your device, and your server only coordinates opaque objects.

Server seesOpaque IDs
Server storesCiphertext
Server cannot readNames or files
You controlEvery key

Built for the whole life of a file.

Push it once, keep a folder in sync, back a repository up, share it safely, or recover it years later.

aqt push

Nothing readable reaches the server.

Filenames, file contents, metadata, and keys are encrypted on your machine before upload.

aqt sync

Sync less. Restore faster.

Folders become a Merkle DAG of encrypted chunks with per-account deduplication.

aqt share

The key stays after the #.

Public links carry their key in the fragment. For private grants, aqt share --with gives read-only access and aqt contacts pins recipient keys.

git push

Push history, not a .git folder.

Git owns commits, refs, and merges; aqt stores the bundles as ciphertext. The server never sees a path, a ref, or an object.

aqt checkpoint

Checkpoint what matters.

Anchor named snapshots, compare them with the live tree, and restore in place or beside it.

aqt tui

The whole vault on one screen.

A lazygit-style dashboard. Live changes, snapshots, and shares, driven by single-key actions that run real aqt commands.

From plaintext to sealed matter.

Blocks converge, encrypt, and move. The network only carries what it cannot understand.

Halftone artwork of stacked encrypted data blocks
Blocks
Halftone artwork of pixels converging into a sealed case
Sealed object
Halftone artwork of a radio tower carrying beams of data
Network

One binary. Three essential moves.

1

Seal a file in one line.

Private is the default. Add --public only when you intend to share.

$ aqt push secret.env
aqt://7yQ2pe
2

Track folders like git.

Two-way sync that merges non-overlapping text edits and keeps a conflict copy when they collide. Preview any of it with aqt diff, or let aqt watch run it for you.

$ aqt sync ~/vault --conflicts=merge
~ merged notes/plan.md
3

Prove the restore works.

Clone on a clean machine or roll a tracked folder back to an anchored checkpoint.

$ aqt restore pre-release
restored ~/vault

The secret stops at your machine.

A key hierarchy you can reason about, from the passphrase you type to the ciphertext the server keeps.

  1. PassphraseYour input.
  2. Argon2idMemory-hard KDF, calibrated on your device.
  3. Root keyUnlocked locally, never transmitted.
  4. XChaCha20-Poly1305Seals every resource with role-separated AADs.

Cryptography

Cipher
XChaCha20-Poly1305
KDF
Argon2id
Keys
Derived locally

Server and transport

Server stores
Ciphertext, opaque IDs
Transport
HTTPS off loopback
Updates
Ed25519-signed manifest

Share links place the content key in the browser fragment. It never appears in the HTTP request.

https://aqt.sh/x/9fK2qd#k.Hs7nT4…

Own the machine. Or rent one.

aqt-server is a static Go binary backed by SQLite and a ciphertext data directory. Put it behind Caddy, systemd, or Docker.

Accounts are managed from the data directory, not a privileged HTTP surface: inspect one, cap its storage, suspend it, or erase it and sweep its ciphertext, with any file left behind named in the receipt.

Read the deploy guide
aqt-serverself-hosted
$ AQT_DATA_DIR=./aqt-data ./bin/aqt-server
$ aqt-server admin accounts quota you@example.com 20GB
  • SQLite
  • Prometheus
  • Native TLS
  • Pure Go

Your files are ready to disappear.

From everyone except you.

curl -fsSL https://web.sync.aquitano.me/install.sh | shiwr -useb https://web.sync.aquitano.me/install.ps1 | iex

Installs to ~/.local/bin. Append -s -- --server for the server binary.

View on GitHub