FAQ

Getting Started

How does XOOUi work?

XOOUi creates a virtual file system for you that is formed by distributing encrypted fragments of your data across two or more cloud drives that you designate. You data is completely encrypted before it is sent to your cloud drives so that no one other than you can ever decrypt it. Unlike other providers of client-side encryption tools, with XOOUi you can reset your passwords on any of your cloud drives or on XOOUi safely without worrying about irrevocable data loss.

What do I need to get started?

You need to have an existing account with at least two of the following cloud drives – Dropbox, Box, Google Drive, Microsoft OneDrive and Amazon Cloud Drive. We will be adding support for more soon – email us if there is one that you want added. If you don’t have existing accounts, you can sign up for free accounts from Box, Dropbox, Google and Microsoft. If you are an Amazon Prime customer, you already have an account with Amazon Cloud Drive

Data Storage

Where is my data stored?

Your data is stored on your accounts on two or more of the following storage providers - Box, Dropbox, Google Drive, Microsoft OneDrive and Amazon Cloud Drive. XOOUi does not provide storage. When you set up your account with XOOUi, you will select the storage providers you are using and will directly authenticate with them. Your data is stored in a separate folder in your accounts on each of the storage providers.

How do you ensure that no one can see my data?

We use the latest in-browser AES-256 bit cipher to encrypt your files with a randomly generated cryptographically secure key. Then your file contents are split and separate chunks are stored on the cloud drives. This ensures that even if any of the drives gets hacked or compromised, all they will get is fragments of data that cannot be deciphered by even the most powerful computers, now or in the future.

But if someone hacks into all my accounts on dropbox, box, google etc., will he be able to get hold of my data?

It's possible, but the likelihood of that happening is extremely low. Most data breaches happen when a service provider is targeted and hacked, rather than a specific user. If you are a public figure or otherwise a target for hackers, XOOUi does offer an additional layer of protection but that comes with the cost of additional complexity. Contact us to know more about this feature.

Authentication

What is n-factor authentication?

n-factor authentication is the logical extension of a popular security protocol used nowadays called two-factor authentication. It simply means that you authenticate yourself to a service using more than one independent authentication method, each of which can be separately verified and securely reset, if necessary. XOOUi allows you to use up to 5-factor authentication. However, we keep it easy to use - we believe security that is intrusive or that imposes onerous restrictions on the user eventually fails to protect.

Does that mean I need to remember encryption keys for my files?

Nope. We believe you should have the freedom to not have to deal with encryption keys. The keys are stored in a patent-pending scheme where the key is fragmented and embedded in the file fragments that are stored on different cloud drives. The key is then automatically regenerated at the time of file access provided you have authenticated yourself to all your cloud drives.

This sounds complicated.

It couldn't be easier. There is no software to install - everything works in your browser. There are no encryption keys to manage. You get a file browser interface that is all point and click. We don't need to know anything from you except a secure way to establish ownership of an account. We currently use your email address to do that, but we will soon support a mobile number and a bitcoin address.

Cost

So what does it cost?

We are currently rolling out a private beta. we do plan to start charging for advanced features, but basic usage will be free. We expect to announce pricing later this year.

Encryption

How secure is your encryption?

We use standard, AES 256 bit encryption with random, cryptographically secure keys being generated automatically for every file stored. For efficiency and speed, we use the WebCrypto APIs available on most modern browsers.

So how are you different from othe client-side encryption solution?

Our aim is to make things simple without compromising our core mission of data privacy. You do not need to manage encryption keys, yet neither Xooui nor your cloud provider can possibly decipher your data. Traditional client-side encryption services require you to mange and protect your passwords or encryption keys yourself. If these are lost or stolen, your data is unrecoverable. With XOOUi, the only passwords you need to remember are the XOOUi password and the passwords to your cloud drives, all of which can be easily reset without ever compromising your data.

How secure is your encryption?

Your data is stored on your accounts on two or more of the following storage providers - Box, Dropbox, Google Drive, Microsoft OneDrive and Amazon Cloud Drive. XOOUi does not provide storage. When you set up your account with XOOUi, you will select the storage providers you are using and will directly authenticate with them. Your data is stored in a separate folder in your accounts on each of the storage providers.