Why ZNode

Storage that answers to you, not to a provider.

Traditional clouds keep your files and the keys to them. Most decentralized networks make you choose between privacy, persistence and simplicity. ZNode Grid is built so you don't have to choose.

vs. traditional cloud

They hold the files. And the keys.

Big cloud drives encrypt your data at rest, but with keys they control. That means the provider can read, scan, lose or hand over your files. ZNode moves the key to your device and the storage to a network nobody owns.

Traditional cloudZNode Grid
Who can read your files

The provider. Files are encrypted at rest, but with keys the provider holds, so staff, scanners and legal requests can reach them.

Only you. Files and their names are encrypted in your browser with a key that never leaves it.

How you sign in

Email and password, often a phone number, and an account the provider can suspend.

A wallet signature. No password exists, so there is none to leak, reset or phish out of a database.

Where the data lives

One company's data centres, under one set of policies.

Three replicas on independent nodes, spread across different operators where possible.

How you pay

A monthly subscription that keeps going up, forever.

One fixed payment, verified on-chain. No subscription.

Where your money goes

To the provider.

90% into a reward pool that only the people running storage nodes can earn from.

Who decides the rules

Terms of service that can change at any time.

A public smart contract. Prices, fees and payouts follow code anyone can read.

vs. Storj & IPFS

Decentralized, without the homework.

IPFS is great for sharing public content, but it doesn't encrypt anything or keep it stored. Storj is private and durable, but it works like a cloud account: monthly bills, its own token and a company running the satellites. ZNode keeps the privacy and durability and drops the rest.

IPFS

Content-addressed sharing. Anyone holding a file's CID can fetch and read it, and the file disappears once nobody pins it any more.

Storj

Encrypted, erasure-coded object storage. Strong engineering, billed monthly, with operators paid in the STORJ token.

ZNode Grid

Sealed in your browser, kept as three self-healing replicas, paid once in ETH under rules set by a public contract.

FeatureZNode GridStorjIPFS
Encrypted before uploadYes:AES-256-GCM in your browser, names includedYes:Client-side encryption in the uplinkNo:Public by default. Anyone with the CID can read it
Stays stored without babysittingYes:3 replicas, automatic repair in ~15 sYes:Erasure coding with automatic repairPartly:Only while someone keeps it pinned
Sign-inYes:Wallet signature, no accountPartly:Account with email and passwordYes:None needed (peer-to-peer)
How storage is paid forYes:One fixed on-chain payment in ETHPartly:Monthly usage billingNo:Not built in. Pinning services or Filecoin
Operator rewardsYes:ETH, claim whenever you like, no held-back escrowPartly:STORJ token, monthly, part held back for new nodesNo:None. Hosting is volunteer
Payout rules enforced byYes:A public smart contractPartly:Satellites run by StorjNo:Not applicable
Storage overheadPartly:3× (full replicas)Yes:About 2.75× (erasure coding)Partly:Depends on how many nodes pin it
CoordinationPartly:A single coordinator todayPartly:Satellites run by StorjYes:Fully peer-to-peer

Where others are stronger, honestly

  • Storage efficiency. Storj's erasure coding stores less overhead than our three full replicas. Full replicas are simpler, and any one copy can serve a download by itself.
  • Scale and track record. Storj and IPFS have years of production use. ZNode Grid is young.
  • Decentralized coordination. ZNode runs a single coordinator today. The whitepaper covers what that means and the plan to go beyond it.

Security

Your key is a signature, not a password.

Your vault key is unlocked from a wallet signature that happens on your device. The servers never see it, so a breached server doesn't mean breached files.

01

Wallet signature

You sign a fixed unlock message. Signing is deterministic, so the same wallet always gives the same result.

02

HKDF-SHA256

The signature hash is stretched into a 256-bit unlock key, inside your browser.

03

Vault key

A random 256-bit key, made once on your device. The server only ever stores it wrapped by the unlock key.

04

AES-256-GCM

Every file and its metadata is sealed with a fresh random IV. Any tampering fails the auth tag.

Every layer sees less than you.

  • Youeverything
  • Backendciphertext index, wrapped key
  • Coordinatoropaque blobs + sizes
  • Storage nodesrandom bytes

A storage node turns malicious

What they getEncrypted blobs with random IDs. No names, no owner, no key.

Why it's not enoughChanged bytes fail AES-GCM's auth tag, and the file is fetched from another replica.

The backend is breached

What they getEncrypted metadata, file IDs and wrapped vault keys.

Why it's not enoughUnwrapping a vault key needs that user's wallet signature, which never reaches the server.

The coordinator is breached

What they getNode addresses and opaque blobs it routes.

Why it's not enoughIt never has a decryption key. Its settler key is limited by the contract to paying registered operators out of the reward pool.

Someone fakes a payment

What they getNothing. Storage is granted only after six checks pass.

Why it's not enoughChain, recipient contract, call data, exact amount, confirmations and the StoragePurchased event are all verified.

Payouts are backed

The contract only credits operators out of the reward pool, so every balance is backed by ETH it already holds.

Nodes prove who they are

Each node signs a fresh challenge with its own key, and must answer at its registered address before it gets traffic.

Internal routes are locked

The backend and coordinator authenticate each other with a shared secret, compared in constant time.

Your part: because your wallet signature unlocks your vault, only sign the ZNode Grid Master Unlock v1 message on this site. A site that tricks you into signing it could decrypt your files. Losing your wallet means losing access too, so keep your seed phrase safe.

Go deeper

The full design,
in one paper.

Architecture, cryptography, the node network, the economics and an honest threat model.