Solutions · Law firms

Exchange files without breaking privilege.

Privileged material sent over email or a generic portal is readable by whoever runs the server. SpaceBox encrypts each document on the sender's device and seals it to the person who should read it, so the file is protected from the intake stage onward and there is nothing for a provider to hand over.

A disclosed privileged file cannot be recalled.

Law firms hold exactly the material that attackers and litigants want, which makes them a standing target. Email attachments, shared drives and generic client portals all leave privileged documents readable by whoever operates the system, and copies accumulate in places nobody treats as storage, from support desks to e-discovery platforms.

Encryption that the provider can undo is not much protection, because the provider can be compelled, or breached. A leaked filing or a disclosed client document does not come back, and a restore does not undo a disclosure. The fix is to keep every file readable only by the intended recipient, so a server holds nothing usable in the first place.

Encrypted on the sender's device, sealed to your key.

Each file is encrypted with AES-256-GCM before it leaves the sender's device, under a key exchanged with post-quantum ML-KEM-768. The private key is generated on the recipient's device and never leaves it, so our servers hold ciphertext and nothing else. Sign-in is a cryptographic challenge rather than a password, so there is no shared secret to phish or leak.

A demand served on i46 returns ciphertext we cannot read, because we never hold the keys. That is the property that matters for privileged work: the confidentiality does not depend on trusting the provider, or on the provider never being breached or compelled.

From confidential intake to per-recipient exchange.

Confidential intake In Lite · now

Turn a device into an encrypted inbox. Clients, sources and opposing parties send documents sealed to your key by scanning a QR invite, with no account and no personal data. You approve each sender, and we store only ciphertext.

Uses → anonymous senders · sealed to your key · zero-knowledge

Privileged exchange Ground

Encrypt each document to the exact lawyer or client who should read it. Add or revoke a party without re-sending to the rest, so removing opposing counsel never touches co-counsel or the client.

Uses → per-recipient sharing · instant revoke

Deal rooms & due diligence Ground

Give each counterparty its own sealed copy of cap tables, board decks and diligence files, and revoke access the moment a party leaves the process. Nothing is ever exposed in the clear to the platform.

Uses → per-counterparty access · ownership transfer

Residency & custody Ground

Keep the archive on EU-hosted infrastructure, or on a 12 TB air-gapped appliance you keep on your own premises with no conventional network interface. Same software, different custody.

Uses → EU Cloud or on-prem Hardware · air-gapped option

The free SpaceBox Lite app covers confidential intake today: 100 MB, 100 files and up to 25 senders, no card and no email. Two-way per-recipient sharing, revoke, ownership transfer and the residency options arrive with SpaceBox Ground. For a real case that shows why intake matters, see the tax documents in the help desk.

SpaceBox is not available to residents of the EU and EEA during the beta. This page is general information, not legal advice.

For law firms, answered.

Can i46 be compelled to hand over privileged files?
A demand served on i46 returns ciphertext we cannot read. Files are encrypted on the sender's device and the private key is generated on the recipient's device and never reaches us, so there is nothing readable for us to produce and no key on our side to decrypt with.
Is it end-to-end encrypted?
Yes. Each file is encrypted with AES-256-GCM before it leaves the sender's device, under a key exchanged with post-quantum ML-KEM-768 (NIST FIPS 203). It is decrypted only on the recipient's device, and our servers hold ciphertext only.
Can I control who sees a document?
With SpaceBox Ground, each document is sealed to the specific recipient, and you can add or revoke a party without re-sending to the others. In the free SpaceBox Lite app, files are sealed to your SpaceBox as an encrypted intake inbox that only your keys can open.
Do clients need an account to send us a file?
No. A sender needs no account and hands over no personal data; they scan your QR invite and are identified only by a key-derived id. You approve each sender before anything is accepted.
Where is the data stored, and can we keep it in the EU or on-premises?
Beta data is stored in Prague on infrastructure i46 operates itself. SpaceBox Ground adds an EU-hosted Cloud option and a 12 TB air-gapped Hardware appliance you keep on your own premises, with the same on-device encryption in every case.
Get started

Confidential intake, encrypted.

Start free with an encrypted intake inbox, and add per-recipient exchange and residency options when you need them. No card, no email.