Security & Encryption

How Gigglade Share protects your data.

Traditional file sharing relies on uploading your data to a central server, hoping the company doesn't read it, get hacked, or sell your metadata. Gigglade Share eliminates the central storage server. Here is the technical breakdown of how we strive to provide a secure environment.

AES-GCM 256-bit

The same encryption standard used by governments and banks to secure highly classified information.

Zero-Knowledge

We do not generate, manage, or hold the cryptographic keys. Your data is invisible to us.

1. The WebRTC Tunnel

When you enter a Room PIN on Gigglade Share, our signaling server facilitates a "handshake" between your device and the recipient's device. Once this handshake is complete, a direct WebRTC (Web Real-Time Communication) tunnel is established.

This means your file travels directly from your IP address to their IP address. It does not pause in a cloud database, it does not get cached on our servers, and it cannot be intercepted by Man-in-the-Middle (MitM) attacks.

2. End-to-End Encryption Architecture

All data channels established via our WebRTC implementation are secured using Datagram Transport Layer Security (DTLS).

  • Key Exchange: Cryptographic keys are generated locally on the communicating devices and exchanged securely.
  • Symmetric Encryption: The actual file chunks are encrypted using AES-256 (Advanced Encryption Standard with a 256-bit key) in GCM (Galois/Counter Mode). This ensures both the privacy (encryption) and the integrity (authentication) of the data.
  • Perfect Forward Secrecy (PFS): New encryption keys are generated for every session. Even if a hypothetical attacker recorded the encrypted traffic and later stole a key, they could not decrypt past sessions.

3. Protection Against Server Compromise

Because Gigglade Share utilizes a Zero-Knowledge architecture, a successful cyberattack against our servers would yield nothing of value regarding your files.

Our servers only process ephemeral routing metadata (SDP offers and ICE candidates) which are required to connect devices. This metadata is held strictly in volatile memory (RAM) and is purged the millisecond the connection is established. There are no databases containing your files to hack.

4. TURN Relays and Firewalls

If a direct peer-to-peer connection fails—usually due to strict corporate firewalls or symmetric NATs—Gigglade Share falls back to using a TURN (Traversal Using Relays around NAT) server.

Even in this scenario, the traffic passing through the TURN server remains completely End-to-End Encrypted via DTLS. The TURN server merely relays the opaque, encrypted packets. It has no cryptographic keys and cannot inspect the payload.

5. Security Audits

We are committed to maintaining the highest security standards. The underlying WebRTC protocols are open-source and continuously audited by the global security community. We regularly monitor our implementation to ensure compliance with the latest cryptographic best practices.

6. Limitations & User Responsibility

While Gigglade Share employs robust encryption protocols, no internet transmission or software system is 100% secure. We provide the platform "AS IS" and disclaim all warranties regarding absolute security. The security of the transferred data ultimately relies on the physical and operational security of your local device and network. Gigglade Inc. is not liable for data breaches resulting from compromised user devices, malware, or network interception.

7. Have a Security Question?

If you are a security researcher or have specific questions about our cryptographic implementation, please reach out to our security team:

support@gigglade.com