HUXOS FSS

Zero-knowledge encrypted file exchange

Share files only the recipient can open. Cryptographically enforced zero-knowledge architecture: encryption and decryption keys are derived entirely client-side. The server stores only ciphertext and provides immutable audit verification receipts.

Launch fss.huxos.io ↗ Request demo
CAPABILITIES

Cryptographic enterprise file exchange

Engineered for banking secrets, regulatory filings, Board communications, and air-gapped infrastructure.

Client-side envelope encryption

AES-256-GCM symmetric encryption executes in browser memory or local SDK before any packet traverses the network boundary.

Cryptographic receipt trails

Every download request generates a signed Ed25519 receipt proving who opened the envelope and at what exact timestamp.

Expiring access windows

Define exact expiration timestamps down to the second. Ephemeral payloads are permanently purged once the threshold arrives.

Dynamic forensic watermarking

Embeds invisible cryptographic watermarks identifying the authorized viewer on PDF, image, and tabular documents.

Remote revocation killswitch

Revoke access to shared documents instantly, preventing any future decryption even if the link has already been opened.

Regulatory compliance

Full alignment with Indonesian personal data protection law (UU PDP No. 27/2022) and OJK banking confidentiality standards.

SPECIFICATIONS

Cryptographic standards and performance

Verified cryptographic parameters evaluated for enterprise compliance.

HUXOS FSS cryptographic implementation specs · September 2026
Standard component Algorithm standard Key size / Mode Compliance status
Payload encryption AES-GCM (Authenticated) 256-bit symmetric FIPS 140-3 compliant
Public key agreement X25519 / ECDH 256-bit Curve25519 RFC 7748 standard
Digital signatures & receipts Ed25519 256-bit Edwards curve RFC 8032 verified
Key derivation function Argon2id / PBKDF2-HMAC-SHA256 64 MB memory / 3 iterations OWASP Recommended
PROTOCOL FLOW

Envelope creation and dispatch

Sample API interaction when an enterprise sends an encrypted file envelope.

POST https://api.huxos.io/v3/fss/envelopes Authorization: Bearer [API_TOKEN] Content-Type: application/json { "recipient_fingerprint": "ed25519:3b04c81a9f02...", "ciphertext_sha256": "4f981b219cf1e4a78103c8...e731b", "storage_bytes": 14829104, "expires_at": "2026-09-28T18:00:00+07:00", "max_downloads": 1, "require_hardware_token": false } /* Response 201 Created — 48ms */ { "envelope_id": "fss_env_01JA98B3", "status": "STAGED_FOR_DELIVERY", "recipient_notification_dispatched": true, "cryptographic_receipt_id": "rec_8f3a09c", "server_payload_visibility": "NONE (CIPHERTEXT ONLY)" }