M
Sign In

Megh

Bringing clouds together.

Scroll

The Opportunity

You already have 82 GB free on the cloud.

Why pay to upgrade?

Google Drive15 GB
Dropbox2 GB
Backblaze B210 GB
OneDrive5 GB
Box10 GB
Mediafire10 GB
pCloud10 GB
Filen10 GB
Yandex Disk10 GB
Total free storage0 GB

You already have 0 GB. For free.

It's just scattered.

Drive
15 GB
MEGA
20 GB
Dropbox
2 GB
pCloud
10 GB
Box
10 GB
Filen
10 GB
Backblaze
10 GB
OneDrive
5 GB

The average user in 2025+ has storage fragmented across 3–7 cloud services. Each with different capacity limits, different interfaces, different security models — and no interoperability between them.

3–7clouds per user
0interoperable
~70%can read your files

Result: wasted storage, fragmented files, cognitive overhead, and security gaps.

Core Promises

One vault. Every cloud.

Megh doesn't just list your clouds side by side. It fuses them into a single, encrypted, OS-native storage pool.

A
B
C
D
One contiguous pool
01

Unified Storage

All connected cloud accounts appear as one contiguous storage pool. A file you save doesn't go to “Google Drive” or “pCloud” — it goes to Megh. Capacity is summed, transparently, across every provider you've linked.

📄
3 GB file
1 GB
1 GB
1 GB
Drive
1 GB left
Backblaze
2 GB left
Dropbox
1 GB left
02

Seamless Cross-Provider Files

A 3 GB file uploads across 1 GB left on Drive + 2 GB left on Backblaze — invisibly. Megh splits at the chunk level, encrypts each chunk independently, and reassembles on read. No provider sees the whole file. No provider knows it's incomplete.

hello.txt
9f3a7c01b2e45d8a1c0fe7b23a4d8c5e4b1a9d2c0e3f7a8b
Driveciphertext
MEGAciphertext
pCloudciphertext
03

Zero-Knowledge Encryption

The server, the cloud providers, and any interceptor see only encrypted noise. Keys never leave your device. Megh's backend can grant access, rotate tokens, or be fully compromised — your files remain unreadable to everyone except you.

📁Megh
📄
📄
📁
📄
📁
📄
macOSWindowsLinuxiOS · soonAndroid · soon
04

Native OS Integration

Real folders on Windows, macOS, Linux — via FUSE and WinFSP. Not a browser tab. Not a sync app. A real filesystem that any app on your computer can read from and write to. Native iOS and Android apps are in active development.

Cryptographic Architecture

Built so that no one can read your files.
Not even us.

Every file is encrypted on your device before it ever touches the network. The keys live only in your device's memory, derived from your password through a memory-hard KDF.

Threats we mitigate

☁️

Compromised Provider

Provider employee or breach accesses stored files.

Client-side encryption. Provider sees only ciphertext.
🖥️

Compromised Megh Server

Attacker gains access to Megh backend.

Zero-knowledge design. Server never has keys.
📡

Man-in-the-Middle

Network traffic interception.

TLS 1.3 + data already encrypted before transit.
📱

Stolen Device

Physical access to user's device.

Device encryption + key in OS keychain.
🔑

Brute-Force Password

Offline password guessing.

Argon2id, 256 MB, 4 iterations.
🔓

Key Compromise

A single key is exposed.

Per-file unique DEKs. Blast radius = 1 file.
⚛️

Quantum Computing

Future quantum attacks on current encryption.

XChaCha20 is quantum-safe for symmetric crypto; hybrid PQ KEM planned for key exchange.

Key Hierarchy

User Master Passwordnever stored anywhere, ever
Argon2id KDF256 MB · 4 iter · 4 parallelism · 32 B salt
Master Key (MK)256-bit · device memory only
Metadata KeyHKDF-SHA-512 · info=“meta”
Encrypts filenames
Encrypts DEKs
Encrypts OAuth tokens
Auth KeyHKDF-SHA-512 · info=“auth”
Verifies MK on login
Recovery KeyShamir SSS · k=3, n=5
Password recovery
Dead-man switch
Per-File DEKs256-bit · unique per file · stored as AES-256-GCM(MK_meta, DEK_i)
chunk₁
XChaCha20-Poly1305
ciphertext₁
chunk₂
XChaCha20-Poly1305
ciphertext₂
chunkₙ
XChaCha20-Poly1305
ciphertextₙ

Cipher Selection & Rationale

File chunk encryptionXChaCha20-Poly1305

192-bit nonce eliminates reuse risk even with billions of chunks. Fast in pure software on all platforms. AEAD provides confidentiality + integrity.

Metadata encryptionAES-256-GCM

Hardware-accelerated (AES-NI) on modern CPUs. Well-audited. Used for filenames, DEKs, and OAuth tokens.

Key derivationArgon2id

Memory-hard. Resists GPU/ASIC brute-force. Winner of the Password Hashing Competition. The "id" variant protects against both side-channel and GPU attacks.

Key expansionHKDF-SHA-512

NIST-standard KDF for deriving multiple sub-keys from a single master key.

Content hashingBLAKE3

Fastest cryptographic hash. Tree-hashable for parallel computation. 256-bit output.

Key recoveryShamir's Secret Sharing

(k, n) threshold scheme: any k of n shares reconstruct the key. Information-theoretically secure.

Why Megh

The only one that actually merges.

Other tools list your clouds. Megh fuses them.

Solution
Merges storage
Splits files across providers
Zero-knowledge encryption
Native OS folders
Mobile
MultCloud
web only
Koofr
rclone
CLI only
Cyberduck
Megh
soon

Stop paying for storage
you already have.

Read the docs

Megh · बादल · মেঘ · ☁ — Bringing clouds together.