End-to-end encrypted storage
ImageTome vs Tresorit
Tresorit is a serious piece of compliance-grade infrastructure. It is zero-knowledge, Swiss-based, owned by Swiss Post since 2021, and it carries the certifications that regulated industries require. It also costs from around $19 per user per month and is sold to organisations rather than to people.
Tresorit and ImageTome use the same primitives. Tresorit sells them to a compliance officer; we give them to a person who wants to share holiday photos.
Side by side
| Criterion | ImageTome | Tresorit |
|---|---|---|
| Encryption model | ImageTome End-to-end. AES-256-GCM in the browser, before upload. | Tresorit End-to-end encrypted with AES-256 and RSA-4096. Keys never leave the client device. |
| Who holds the keys | ImageTome You. An RSA-4096 private key generated on your device and never sent to us. | Tresorit You, with enterprise key management and admin recovery options on business plans. |
| What an account needs | ImageTome A username. No email address, no password, no phone number. | Tresorit An email address and a password, usually provisioned by an organisation. |
| If you lose access | ImageTome Nothing we can do. Your exported key backup is the only route back in. | Tresorit Admin-assisted recovery on business plans, which is a feature for companies and a consideration for individuals. |
| Filenames and titles | ImageTome Encrypted. Tome names, descriptions, filenames, titles and post bodies. | Tresorit Encrypted filenames and folder structure. |
| Content scanning | ImageTome None, and none is possible. Nothing here is detected proactively, because nothing can be read. | Tresorit Not possible on file contents. |
| Video | ImageTome MP4 and WebM up to 200MB, with thumbnails generated and encrypted in the browser. | Tresorit Stored as files. No media-specific handling. |
| Sharing | ImageTome Invite by username. The tome key is wrapped with their public key. | Tresorit Encrypted share links, data rooms, granular permissions and access logs. |
| Discussion | ImageTome Encrypted comments on posts, images and videos. | Tresorit No commenting on media. Collaboration is document-centric. |
| Verifying the claim | ImageTome Open your network tab during an upload and read what is actually sent. | Tresorit SOC 2 Type II, ISO 27001, ISO 27018 and HIPAA compliance. Closed source. |
The same cryptography, aimed at a different person
Tresorit's model is AES-256 content keys wrapped with RSA-4096 per recipient, with the private keys held on the client. That is, in outline, the same construction we use, and it is a well-worn design because it works.
The difference is everything built on top. Tresorit adds data rooms, eSign, access logs, user-level data residency and admin controls, because its buyer is an organisation that must demonstrate compliance to a regulator. It also adds an administrator who can recover a user's data, which is exactly what a business needs and exactly what an individual might not want.
ImageTome has no administrator with that power. There is no company account above yours, no admin recovery, and nobody who can be asked to open your tome. For a hospital that is a missing feature. For a person sharing family photos it is the point.
Cost and commitment
Tresorit's Professional plan runs around $27.49 a month for a single user, and its Business tiers start near $19 per user per month with minimum seat counts. That is defensible pricing for a compliance product and prohibitive for sharing a wedding album with eleven relatives.
ImageTome asks for a username. There is no seat count, no minimum, no invoice and no email address to give.
Documents versus media
Tresorit is document-centric. It handles files, permissions and audit trails, and photographs are just files with large byte counts.
A tome is media-centric. Video thumbnails are generated on your device and encrypted before upload so a gallery can be browsed without decrypting whole videos. Comments live under individual images. Posts hold writing next to the pictures it is about. All of it under one AES-256-GCM tome key.
When Tresorit is the better choice
- If you have a regulatory obligation, Tresorit has SOC 2 Type II, ISO 27001, ISO 27018 and HIPAA, and we have none of them. Auditors do not accept "look at the network tab".
- If an organisation must retain access to a departing employee's files, Tresorit's admin recovery does that and our design forbids it.
- If you need access logs, granular permissions, data residency controls or eSign, Tresorit has built all of it.
- Swiss jurisdiction and Swiss Post ownership are a real institutional guarantee of a kind a small service cannot offer.
ImageTome and Tresorit, asked and answered
Yes. Tresorit is end-to-end encrypted with AES-256 and RSA-4096, encryption keys stay on the client, and Tresorit cannot read your files. Business plans add administrator-assisted recovery, which is a deliberate organisational feature rather than a weakness in the cryptography.
For an individual or a small group sharing photos and video, yes, and at no cost. For a regulated business needing certifications, audit logs and admin recovery, no. We have deliberately not built the administrator that a business needs.
Because an administrator who can recover your data is an administrator who can read it, and anyone who can compel that administrator can read it too. Removing that role is the entire security argument.
No. If you need SOC 2, ISO 27001 or HIPAA on paper, Tresorit is the correct choice and we are not.
Sources
- Tresorit business review 2026, iFeeltech
- Tresorit review 2026: AES-256 zero-knowledge and Swiss jurisdiction, Priviy
Claims about Tresorit were checked against the sources above on 30 August 2026. Products change. If something here is out of date or wrong, we would rather fix it than keep it.
Other comparisons
vs Proton Drive
Proton is a general encrypted drive with an account you can recover. We are an encrypted media space with an account nobody can recover, including us.
End-to-end encrypted storagevs MEGA
Both encrypt in the browser. The question a 2022 research paper asked of MEGA is the question you should ask of us too: what happens if the server turns hostile?
Mainstream cloud photosvs Google Photos
Google encrypts your photos and keeps the keys. We encrypt your photos and never have the keys.
Try the version where nobody holds your key.
One username, one tome, and a look at your own network tab to check we mean it.
Create an account