End-to-end encrypted storage
ImageTome vs Proton Drive
Proton Drive is the real thing. It is end-to-end encrypted, it encrypts metadata, it comes from a company with a long record on privacy, and it is audited. If you are choosing between us, you are choosing between two honest answers to the same question.
Proton is a general encrypted drive with an account you can recover. We are an encrypted media space with an account nobody can recover, including us.
Side by side
| Criterion | ImageTome | Proton Drive |
|---|---|---|
| Encryption model | ImageTome End-to-end. AES-256-GCM in the browser, before upload. | Proton Drive End-to-end encrypted, including file metadata. Open source clients, closed source server. |
| Who holds the keys | ImageTome You. An RSA-4096 private key generated on your device and never sent to us. | Proton Drive You, derived from your account password, with a recovery phrase as a backup. |
| What an account needs | ImageTome A username. No email address, no password, no phone number. | Proton Drive A Proton account with an email address and a password. |
| If you lose access | ImageTome Nothing we can do. Your exported key backup is the only route back in. | Proton Drive A 12-word recovery phrase restores access and decrypts your data. Email or SMS recovery restores the account but leaves data encrypted. |
| Filenames and titles | ImageTome Encrypted. Tome names, descriptions, filenames, titles and post bodies. | Proton Drive Encrypted, including filenames. |
| Content scanning | ImageTome None, and none is possible. Nothing here is detected proactively, because nothing can be read. | Proton Drive Not possible on file contents. |
| Video | ImageTome MP4 and WebM up to 200MB, with thumbnails generated and encrypted in the browser. | Proton Drive Stored and shared as files. Rebuilt platform in June 2026 improved galleries and upload speed. |
| Sharing | ImageTome Invite by username. The tome key is wrapped with their public key. | Proton Drive Encrypted share links and folder sharing, including to people without an account. |
| Discussion | ImageTome Encrypted comments on posts, images and videos. | Proton Drive No commenting on media. |
| Verifying the claim | ImageTome Open your network tab during an upload and read what is actually sent. | Proton Drive Client code is open source and independently audited. The server is not. |
Both zero-knowledge, different root of trust
Proton derives your encryption keys from your account password, with a 12-word recovery phrase as the backup route. That is a well-understood design and it gives you something we deliberately do not have: a way back in. Write down the recovery phrase, lose your laptop, and your files are still there.
ImageTome has no password at all. Your RSA-4096 private key is generated in the browser at registration and stored on your device. There is nothing derived from a secret you might reuse, nothing to phish and no password database. There is also no recovery phrase we issue and no reset flow. You export a key backup or you eventually lose the account.
Neither design is strictly better. Proton's is more forgiving and depends on a password you must keep strong. Ours removes the password as an attack surface entirely and moves the whole burden of custody onto you.
A drive, and a place to put photos
Proton Drive is storage. It holds any file, syncs across devices and shares by link. Photos and videos are files like any other, and as of 2026 the gallery experience is much improved.
ImageTome is not a drive. A tome is a shared space with members, roles, posts, encrypted comments underneath each photo and encrypted one-to-one messaging alongside. It is closer to a private, encrypted group album than to a folder. If what you want is somewhere to back up documents, Proton Drive is the right tool and we are the wrong one.
What each of you has to trust
Proton publishes its client code and commissions independent audits, which is more transparency than most services offer. Its server code is closed. In practice that is fine, because in a properly built end-to-end system the server is not supposed to be trusted, but it does mean the delivered client is the thing you are relying on.
That is true of us too, and we would rather say it plainly than claim otherwise: any browser-based encryption depends on the code the server sends you. The check available to you is direct and worth doing. Open your browser's network tab during an upload and look at what leaves your machine. If it is ciphertext, the claim holds for that upload.
When Proton Drive is the better choice
- If you want account recovery, Proton has it and we do not. A recovery phrase you can store in a safe is a genuinely better answer for most people than a key backup with no fallback.
- If you want to store documents, spreadsheets and archives as well as media, Proton Drive is general-purpose storage and we are not.
- If you want independent audits and open source clients, Proton has both today. It is a larger company with a longer track record, and that is worth something.
- If you need to share with people who will never make an account, Proton's encrypted share links do that. Our invitations require the other person to have a keypair.
ImageTome and Proton Drive, asked and answered
Yes. Proton Drive is end-to-end encrypted, encrypts file metadata including filenames, and Proton cannot read your files even under legal compulsion. It is one of the few mainstream services where the claim holds architecturally.
If you want no email address attached to your account, no password anywhere in the system, and a space built around shared media with encrypted comments and messaging rather than a folder of files. If you want general encrypted storage with a recovery path, Proton Drive is the better fit.
No. We have a key export you perform yourself and store yourself. There is no phrase we can issue that recovers your account, because we hold nothing to recover it from. Export a backup on the day you sign up.
Sensibly, yes. Proton Drive for documents and long-term storage, a tome for the photos and videos you want shared with a few specific people and read by nobody else.
Sources
- Protect your data with zero-access encryption, Proton
- Recovery phrase, Proton Support
- Restoring Proton Drive files after a password reset, Proton Support
Claims about Proton Drive were checked against the sources above on 30 August 2026. Products change. If something here is out of date or wrong, we would rather fix it than keep it.
Other comparisons
vs MEGA
Both encrypt in the browser. The question a 2022 research paper asked of MEGA is the question you should ask of us too: what happens if the server turns hostile?
End-to-end encrypted storagevs Tresorit
Tresorit and ImageTome use the same primitives. Tresorit sells them to a compliance officer; we give them to a person who wants to share holiday photos.
Mainstream cloud photosvs Google Photos
Google encrypts your photos and keeps the keys. We encrypt your photos and never have the keys.
Try the version where nobody holds your key.
One username, one tome, and a look at your own network tab to check we mean it.
Create an account