Secure file management across all your devices

Browse, preview, copy and manage files on any device from any other device, with no user accounts, no passwords and no cloud storage. Your devices form a private fleet and move files directly between themselves, locally or over the internet, encrypted end to end using post-quantum key exchange.

macOSWindowsLinuxiOSAndroid
Your devices prove themselves to each other, using the security hardware built into each one. Files move directly between them, sealed from end to end. No cloud storage. No login in the path. Nothing for an attacker to aim at.
International Cyber Expo, 29 to 30 September 2026, Olympia, London
Launching at

International Cyber Expo 2026

Olympia, London, 29 and 30 September 2026. FILOTRON Professional and FILOTRON for Enterprise launch there. See FILOTRON running on stand K73.

Two editions. One fabric.

FILOTRON Professional for your personal devices.
FILOTRON for Enterprise for your organisation's devices.

For you

FILOTRON Professional

Reach whatever is on your Mac, PC, Linux machine, iPhone or Android from any of your other devices, wherever you are.

Open any of your devices from any other and browse its folders. Pull just the file you need, straight to the device in your hand.
  • Pull, don't just push. Nothing to pre-sync: browse a device's files and grab what you need, on demand.
  • Only you can read them. Files travel encrypted end to end and are never stored on our servers.
  • 100% anonymous. Sign in once to subscribe and set up each device; after that, no account is involved.

FILOTRON Professional →

For your organisation

FILOTRON for Enterprise

Adds user authentication with your identity provider, plus access control and auditing, once devices have authenticated.

First, the devices prove themselves to each other. Then the person signs in with the identity provider you already use, and their roles decide what they may do.
  • Sign in the way you already do. Staff use the same work sign-in they use every day; Microsoft and the other big names are supported.
  • You decide who sees what. Give each person or team exactly the folders they need; change your mind and access is gone in minutes.
  • Your business stays your business. It runs on your own equipment and every action is recorded in your own records.

FILOTRON for Enterprise →

Both editions run on FILOTRON Fleet Fabric.


Fleet Fabric is the system that lets a pair of your devices find each other, prove themselves to each other, and move files between them, using the Hardware Security Module already built into each device, and mutual TLS.

Each device's certificate holds an opaque fleet identifier and a public key born in the device's Hardware Security Module; the private key never leaves it. No user or organisation identifying data is in the certificate, so the most exploited attack surface, user credentials, does not exist in the fabric. Every connection is mutually authenticated below the application layer: zero trust by architecture.

Eighty-five seconds, five chapters: how the fabric works, and why there is no credential in it to steal. Use the chapter buttons to jump.

FILOTRON moves files between your devices with no username, no password, no passcode, and no cloud store. Here is why that is safe. Each device generates its own key pair inside its Hardware Security Module: Secure Enclave, TPM 2.0, StrongBox. Only the public key leaves, to be signed by the fleet's Certificate Authority. The app carries the FILOTRON root certificate, pinned. The app carries your organisation's own root certificate, pinned (Advanced and High-Assurance editions). Enrolment is the one moment an account or an administrator is involved. The private key never leaves the hardware. Both devices present certificates. Each checks the other's chain up to the pinned root, and the four FILOTRON certificate extensions. Then each proves it holds the private key by signing the handshake inside its hardware. A copied certificate cannot do that. Only after both proofs does a connection exist. No password was typed. There is none to type. A device outside the fleet is refused before a byte moves. The session key comes from a post-quantum key exchange: X25519 with ML-KEM-768, over QUIC. Files move directly, device to device, encrypted end to end. Traffic recorded today cannot be decrypted by a future quantum computer. If the route needs a relay, it forwards sealed blocks and holds no key. One fabric on macOS, Windows, Linux, iOS and Android. On the same network, devices find each other directly. Across the internet, a switchboard passes connection details only; it never sees a file. Any device reaches any other, with the same proofs every time. No login in the fabric. No central store. Keys that never leave the hardware. Hardware governs admission · Identity governs authorisation. You cannot phish a login that does not exist. FILOTRON Fleet Fabric, Patents-pending. FILOTRON for Enterprise adds your identity provider, roles and audit above the fabric. The fabric itself still has no credential to steal.
0:00 / 1:25
A key pair is generated inside the device's Hardware Security Module. Only the public half is sent to the Certificate Authority for signing. The fleet's certificate comes back and sits beside the key. The private key never leaves the hardware. Nothing can copy it out.

01Keys born in hardware

Every device generates its own key pair inside its Hardware Security Module: Secure Enclave, TPM 2.0, Android StrongBox or TEE, Windows TPM. The private key is non-exportable: it never exists outside the hardware. A device with no security module at all is flagged with a permanent warning in FILOTRON Professional, and is not admitted to a FILOTRON for Enterprise fleet.

Each device presents its certificate to the other. Each checks the other's certificate against the fleet's pinned Root CA. Only when both checks pass does a connection exist. A device without a fleet certificate is refused before a byte moves.

02Mutual TLS: both sides prove themselves

No device is trusted for being on the network. Both ends of every connection present a fleet certificate and verify the other's against the pinned Root CA before any data moves. A device outside the fleet is refused at the boundary.

Encrypted on the source device… …if the route needs a relay, it passes sealed blocks it has no key for… …and decrypted only on the destination device. The key exchange is post-quantum: X25519 with ML-KEM-768, over QUIC.

03Sealed from source to destination

Transfers run over QUIC with mutual TLS and post-quantum key exchange. There is no server anywhere that can read them: when a connection has to be relayed, the relay forwards ciphertext and holds no key.

On the same network, devices find each other directly. Across the internet, a switchboard passes connection details only… …then the devices connect directly. The switchboard never sees a file.

04Find each other anywhere

Devices discover one another directly on the same network, or over the internet through a switchboard that carries connection details only. Files move device to device, never through the switchboard.

Hardware governs admission · Identity governs authorisation

User authentication, role-based access control and auditing sit above the fabric, not inside it. That is what FILOTRON for Enterprise adds, on top of the same hardware-rooted connections FILOTRON Professional uses.

hardware-born keys · X.509 mutual TLS · QUIC · post-quantum key exchange (X25519 + ML-KEM-768) · built on the FIPS 140-validated AWS-LC module · patents-pending, four UK patent applications

chip: cannot be copied PIN: can be copied

A stolen password has nowhere to be typed.

Your bank card carries two things: a chip that cannot be copied, and a PIN that can. Steal one and you have nothing. The security isn't that either is unbreakable; it's that they are different kinds of thing. A password on its own is all PIN and no chip.

FILOTRON puts the chip back. Every device proves itself in hardware before anyone can sign in, so a phished password reaches a slot with no card in it.