Encrypted cloud storage is not one product category. Proton Drive and Tresorit are services built around end-to-end encryption. Cryptomator is a client-side encryption layer that creates vaults inside storage you choose. All can reduce a provider's ability to read file contents. They differ sharply in sharing, recovery, collaboration and operational burden.
Start with the failure you care about
End-to-end encryption is useful when you do not want the storage provider to possess the ordinary key needed to read your files. It does not prevent malware on an unlocked computer, a recipient from copying a shared document, accidental deletion, a weak account-recovery process or exposure through an unencrypted export.
Name the data and adversary. Family photos, tax records, collaborative work and a journalist's source archive have different availability and sharing requirements. If losing access would be worse than provider access, recovery deserves as much attention as encryption.

Compare seven things before price
- Key custody. Who can decrypt ordinary stored content, and under which sharing modes?
- Metadata. File contents may be protected while account, billing, access and network metadata remain visible.
- Recovery. Determine what happens when the password, device or second factor is lost.
- Sharing. Public links, invited collaborators and downloaded copies create different boundaries.
- Platform fit. Confirm desktop, mobile, web and offline behavior on the exact devices you use.
- Versioning and backup. Sync is not backup. Deletion and ransomware can propagate.
- Exit. Test whether a complete, readable export can be made without proprietary structure.
Proton Drive: integrated encrypted storage
Proton says Drive encrypts file contents and key metadata on the user's device with end-to-end encryption, so Proton does not hold the ordinary decryption key. Its official sharing documentation includes invitations and links, with controls such as passwords, expiration and revocation depending on the current interface and plan.
Fits: individuals and families who want an encrypted service without building a vault layer. Tradeoff: encrypted collaboration can have different feature depth from mainstream office suites, and using the same provider for email, password management and files concentrates account-recovery importance.
Before migrating, confirm folder sharing, photo workflows, offline access and the exact recovery method. Do not interpret “zero access” as zero metadata or zero account risk.
Tresorit: managed encrypted collaboration
Tresorit states that files are encrypted on the device before upload and that intended users hold decryption access. Its product is oriented toward controlled sharing, administration and business workflows, including policies and access management that vary by plan.
Fits: teams that need encrypted storage plus centralized administration and repeatable external sharing. Tradeoff: more management capability means more settings, cost and policy work. An administrator can govern access without necessarily possessing file plaintext, but organizational accounts and exports still require careful offboarding.
Test a real collaborator workflow. Verify whether recipients need accounts, how revoked links behave, what audit information is available and who owns files when an employee leaves.
Cryptomator: bring your own cloud
Cryptomator is open-source client-side encryption software. It creates a vault whose encrypted files can be placed in a local sync folder or compatible cloud location. The cloud provider sees encrypted objects rather than ordinary file contents and names, while Cryptomator handles encryption and decryption on the device.
Fits: people who want to keep Dropbox, OneDrive, Google Drive or another storage layer while adding their own vault. Tradeoff: collaboration, mobile access and recovery are less seamless. Sharing the raw encrypted folder is not the same as sending a convenient document link, and vault-password loss can be final.
Cryptomator does not turn the underlying provider into an end-to-end encrypted collaboration suite. It separates storage from encryption. That separation is powerful when you accept the extra operational work.
The no-buy option
If the current cloud contains mostly replaceable media and low-sensitivity documents, start by removing stale files, enabling strong account security and making an independent backup. Put the small sensitive subset into an encrypted archive or an operating-system-encrypted local drive. A new subscription cannot compensate for a single copy and an untested recovery plan.
A two-week migration protocol
- Inventory data by sensitivity, collaboration need and replacement cost.
- Choose a pilot folder with ordinary—not irreplaceable—files.
- Enable a strong unique password and two-factor authentication; record recovery material offline.
- Sync the pilot to every required platform and test offline access.
- Share one test file, revoke it and inspect the recipient experience.
- Delete and recover a file. Then simulate losing one device.
- Export the pilot in ordinary readable formats.
- Move sensitive data only after the recovery and exit tests pass.
Keep at least one independent backup that is not continuously synchronized. For family archives, document the recovery path so another trusted adult can use it. The custody framework in Private Note-Taking Apps and account discipline in Password Managers Without the Hype apply here too.
Who should skip each option
Skip Proton Drive if your essential collaborative workflow is unsupported. Skip Tresorit if you do not need team controls and will resent maintaining them. Skip Cryptomator if losing a separate vault password is likely or if nontechnical collaborators need frequent browser-based access. Skip all three as a buying decision until you know whether confidentiality, backup or sharing is the actual problem.
Official sources and volatile details
- Proton, Drive security and encrypted file sharing.
- Tresorit, security overview and encryption whitepaper.
- Cryptomator, security architecture and vault management.
This is a workflow comparison, not a security audit or guarantee. Verify current platform support, sharing behavior, plan limits and recovery documentation before moving important files.
END OF FIELD GUIDE 026
Keep the question. Test the model.
Choose the narrowest claim the evidence can carry, then leave room for revision.