73 karma · joined May 2, 2025
I am late to the party, but I was also building in this space in the last year,
Basically I did a peer to peer filesystem named keibidrop: https://keibidrop.com/
I made it public last week. It does what local send does, but also via WAN. Still did not launch the mobile apps.
And 1 up is that it has also a virutal filesystem that is synced both ways.
repository is here: https://github.com/KeibiSoft/KeibiDrop
The code is open source, except for the UI, and I did benchmark on loopback vs localsend (local send is faster :D )
https://keibisoft.com/blog/keibidrop-benchmarks-vs-competiti...
and was also trying to get a commenting thread in /r/golang yesterday!
behind the hood I went with PQC, + gRPC + FUSE.
Both peers mount a virtual FUSE folder. Files shared by one side appear in the other's folder in real time. You can open, copy, and browse your peer's files as if they were local. Files go directly between devices over encrypted gRPC. (by default it tries over LAN, then direct IPV6, then uses a data relay).
The hardest part has been making git repos work through the FUSE mount between peers.
(Been developing the tool for 12 months now, very close to a full release)
A) I tie the cybersecurity activities to business revenue enabling outcomes (unblocked contracts), and second to reduced risk (as people react less to this when spending the buck).
B) with the political capital from point A) I actually operate a cybersecurity program, justify DevSecOps artefacts, threat modeling, incident response exercises, etc.
What this SOC2 reports, ISO27k certificates are, more like a standardization for communicating the activities of the org to outside people, and getting an external person to vet that the org doesn't bulls*t too much. but at the end of the day, the organization is responsible for keeping their house in order.
I always struggle to share files between my devices, or to navigate them. Why do I need servers, or dropbox or wetransfer?
Inspired by croc, rclone, syncthing and magic wormhole, I'm close to releasing KeibiDrop as MPL2.0.
It has a nice slint.dev GUI, works cross platform on mobile, + desktop (via FUSE or no-FUSE), and has post quantum encryption at transport level.
No clear monetization path, but I also tinker with unikraft in order to host a relay server (for key negotiation, or other things) as a unikernel cloud function.
https://docs.slint.dev/latest/docs/slint/guide/backends-and-...
But, I have only used it with Romanian and English.
Try here: https://slintpad.com/. (just replace the Text with TextInput) and see if it works.
The only one I could find in Delaware with YBC Holdings, INC is registered in 1994 and is a brewing company
https://b.assets.dandb.com/businessdirectory/ybcholdingsinc....
How do you monitor and enforce your uptime SLA? You state 99.9%, which is less than 9 hours downtime per year; what happens if you breach this guarantee?
Any other types of SLA's? What happens if you get breached/ your networks gets breached, or hardware failure, and my "anonymous" data is lost.
Besides that you make some claims, but are they real, or are they vaporwave?
like: "All our datacenters maintain the highest security standards with 24/7 on-site security, biometric access controls, and CCTV surveillance.
Each facility features N+1 power redundancy with UPS systems and diesel generators, ensuring your services remain online even during extended power outages."
Are you sure the above is true, because I am not.
Here on datacenters you say your are ISO27001 and SOC2 certified.
"We're ISO 27001 certified and maintain SOC 2 Type II compliance."
You do not have any certificate that I can find: https://www.iafcertsearch.org/search/certified-entities?sear...
https://www.iafcertsearch.org/search/certified-entities?sear...
Who is the company who certified you? What is the certification number?
What is the definition of wasting developer time? If a developer takes a 2 hours break to recover mental power and avoid burnout, is it considered time wasted?
It's just that the entry level for adopting a new tool (for other people) is:
Convince my recipient to use this system instead of "Why not just send the password as we usually do on our secret chat."
And then we spend 20 minutes talking about it and me advocating for their unknown and unaccountable creator.
And your flow is: I encrypt my password; I upload the encrypted password to your server.
And I share the password to the encrypted password as plain text.
Why do I have to upload the encrypted password to your server, and not just use signal disapearing messages, or telegram secure channel disappearing messages to share the encrypted password there.
And I can use any other side channel to share the second password, like whatsapp, or regular plain mail.
It feels to me that you made a two step process into a one step process but increased the risk by adding you in the middle.
Why would I offload my trust to you instead of doing the second step?
Remote: Yes
Willing to relocate: No
Technologies: Golang, Rust, Haskell, FUSE, secure infra, cryptography, compliance systems, ISO 27001 / NIST / SOC2, backend systems, BCP/ISMS
Résumé/CV: Available upon request
Email: ciso.contracts.compound504@slmail.me
Security-focused backend/devops engineer with experience in regulated industries. Served as CISO for two startups that were acquired (IBM + Dataminr buyers). Built secure infrastructure, compliance automation, and ISMS/BCP systems that helped land enterprise clients including BCG, Palo Alto Networks. I speak both code and risk, and I thrive where technical architecture meets business requirements.
Looking for high-leverage contract work, virtual or fractional CISO roles, or backend-heavy infrastructure projects in industries where trust and uptime matter.
Note: Email alias via SimpleLogin. Replies go straight to me.