qARX Drop — secure, ephemeral one-time secret sharing service for qARX
661
qARX.Drop — zero-knowledge, one-time secret sharing for recipients who do not have a qARX account. Part of qARX, the self-hosted, end-to-end encrypted Secret Manager. Your Digital Fortress.
Go service (Echo) with an embedded SQLite store. The Portal encrypts the payload
client-side with a random one-time key; that key travels only in the URL fragment
(#), which browsers never send to a server. Drop stores an opaque ciphertext it
cannot decrypt, enforces view limits and TTL, and deletes the blob when it expires or
is burned.
Security airgap by design: Drop is the internet-facing component and keeps its own SQLite database. It has no access to the vault database, and compromising it exposes zero plaintext.
Drop is deployed as part of the qARX stack. Generate the full compose.yml from the
Core image:
docker run --rm wearequantico/qarx-core:latest qarx-cli compose > compose.yml
Full installation & deployment guide: https://quanticoarx.com
| Setting | Notes |
|---|---|
| Listen port | 8081 (published on 127.0.0.1:8081 by the generated compose file) |
| Health probe | /livez |
| Persistence | SQLite at DROP_DB_PATH (/data/qarx-drop.db) — mount a volume |
| Public URL | DROP_PUBLIC_URL — must be reachable by external recipients over HTTPS |
| Shared secrets | DROP_CORE_TO_DROP_KEY, DROP_DROP_TO_CORE_KEY (HMAC, generated by qarx-cli env init) |
| Limits | DROP_DEFAULT_TTL (24h), DROP_MAX_TTL (720h), DROP_MAX_VIEWS_MAX, DROP_MAX_BLOB_SIZE, per-IP rate limits |
| Egress | DROP_GEOIP_ENABLED (default true) geolocates access-log IPs via a third-party service; set false for zero outbound traffic |
Drop is deliberately kept off the internal network: it never reaches PostgreSQL or Redis.
:X.Y.Z — specific release (recommended; pin by digest in production):latest — most recent releaseCore, Portal and Drop are released in lockstep — always deploy the same tag for all three.
wearequantico/qarx-core — backend APIwearequantico/qarx-portal — web UIwearequantico/qarx-drop — one-time secret sharing (this image)Zero-knowledge architecture: the decryption key lives only in the URL fragment held by the sender and the recipient. Drop stores ciphertext exclusively and can never read what it distributes.
Report vulnerabilities to [email protected].
Proprietary © Quantico S.r.l. Sharing via qARX.Drop is a license-gated feature. See https://quanticoarx.com Support: [email protected]
Content type
Image
Digest
sha256:08b993dad…
Size
10.9 MB
Last updated
8 days ago
docker pull wearequantico/qarx-drop