SurePack: Anonymous, Quantum‑Resilient Secure File Sharing

A business case for revolutionizing secure file transfer with post-quantum cryptography and user-friendly design

The Problem: Insecure File Sharing is Costly and Outdated

Despite living in an age of daily cyber threats and strict data regulations, businesses still struggle with secure file transfer. Employees routinely bypass IT safeguards71% of office workers globally admit to sharing sensitive company data through unauthorized messaging and collaboration tools. This behavior exposes organizations to breaches and compliance penalties. In Australia, the average data breach now costs AUD $4.26 million (≈USD $2.8M), a 27% increase since 2020. Such incidents aren't rare – phishing and stolen credentials are leading causes – and they underscore a critical need for better secure communication channels.

Meanwhile, traditional encryption solutions have failed to gain broad adoption due to complexity. PGP, once the go-to tool for encrypting files/email, is now considered antiquated – security experts bluntly state that "PGP is bad and needs to go away". Its 1990s design and clunky user experience mean that no competent crypto engineer would build a system like PGP today. Usability studies famously showed even tech-savvy users struggling for hours to set up PGP properly. In practice, most people simply won't use such cumbersome tools, leaving sensitive files unencrypted and sent over email or consumer cloud drives. The bottom line: organizations lack a user-friendly, modern way to share files with strong end-to-end encryption. This gap between security needs and practical tools presents a major opportunity.

The Solution: SurePack Overview

SurePack is a next-generation secure file transfer platform designed to fill that gap. It delivers end-to-end encrypted file sharing with anonymity and ease of use – essentially "PGP for 2025" but without the pain points. SurePack consists of two main components:

How it works: Users generate an anonymous digital identity (an X.509 certificate) with a simple command. The system produces a random, memorable alias comprising three words (e.g. crow-mandate-current.publickeyserver.org) as the certificate name. This serves as the user's public address on the Suredrop server. No personal details or login are required – the design follows an Anonymous Certificate Enrollment (ACE) protocol, meaning anyone can obtain a certificate without disclosing their real identity. (If desired, an email or name can be optionally bound to the cert, but it's not required.) The three-word alias is easy to communicate and verify, unlike long PGP key fingerprints. It's even a valid DNS name – entering the alias URL in a browser will fetch that user's public key certificate for verification.

With an alias in hand, secure sharing becomes straightforward:

From a workflow perspective, SurePack feels simple: users exchange human-readable aliases, not long keys; creating and sending an encrypted bundle is as easy as zipping files; and receiving is as easy as checking an inbox. All the complexity (key generation, encryption, signature, server upload/download) is handled behind the scenes by the SurePack client and server.

Key Features and Innovations

1. Anonymous PKI with Easy Verification

SurePack introduces an Anonymous Certificate System that provides the trust of Public Key Infrastructure (PKI) without the usual overhead. The three-word random aliases act like self-chosen email addresses for encryption. Key features:

(For cases where identity is important, the system allows optional binding of an email to the certificate and lookup by that identity. But if anonymity is preferred (e.g. whistleblowing, confidential tips, or simply privacy-conscious collaboration), the alias alone suffices.)

2. Strong Hybrid Encryption (Post-Quantum Ready)

Each file package is secured through multiple layers, combining time-tested algorithms with cutting-edge cryptography:

The result is a system that meets or exceeds modern cryptographic best practices. Unlike PGP's dated ciphers and lack of forward secrecy, SurePack employs forward secrecy by design (one-time keys) and up-to-date primitives. Security engineers have long called for such measures – e.g. key management that is transparent to users, forward secrecy, and "cryptography that post-dates the Fresh Prince" (i.e. anything but 1990s algorithms). SurePack delivers exactly these elements in a cohesive package.

3. End-to-End and Zero Trust

SurePack ensures that only the intended recipients can decrypt files – not even the server operator (us) can read the data. The server simply relays encrypted packages and stores public certs. This aligns with a zero-trust philosophy and gives clients confidence that their sensitive files (financial records, contracts, IP, personal data, etc.) remain private. Even if our server or S3 storage is compromised, the attackers get only gibberish ciphertext. End-to-end encryption is increasingly a baseline expectation – for example, over 90% of web traffic is now sent over HTTPS, and popular messengers like WhatsApp and Signal have familiarized users with E2E encryption for messages. SurePack brings that same level of protection to file transfers.

4. Integrated Delivery Network

Unlike PGP which only handled encryption and left actual delivery to email or other means, SurePack integrates the delivery mechanism via Suredrop. The user doesn't have to separately figure out how to share the ciphertext – the system seamlessly provides a drop-box style delivery. This makes it far more convenient to use. It also adds features like download tracking and expiration – the server can note when a package was picked up and can enforce one-time download or auto-delete after a period, reducing lingering sensitive data. (Packages are typically removed from the server once all recipients have downloaded, or after a certain time-to-live, to minimize exposure.)

5. Short-Lived, Revocable Credentials

Each SurePack certificate (alias) is intentionally short-lived and disposable by default. This is a security design choice: if a key is compromised, it limits the damage window. Users are encouraged to generate new aliases over time or for different contexts. (The system could implement revocation lists or automatic expiration to enforce this in future updates.) This contrasts with PGP's model of long-lived keys tied to identities, which experts criticize as risky. Here, if there's any concern a private key might be exposed, the user can simply create a new alias/certificate and move on – no extensive "web of trust" fallout. Ephemeral keys and identities by default make the system more resilient.

6. Full-Featured Client and API

The SurePack client already supports a comprehensive set of operations (as a result of our completed development effort). Users can create identities, pack/unpack files, send/receive packages, list incoming files, verify certificates, and even launch a GUI for those less command-line inclined. The inclusion of a GUI is important for adoption – many users prefer a simple visual interface, and we have that covered. For power users or integration into other software, the client's CLI and the open RESTful API mean the solution can be scripted or built into other tools. For example, a company could integrate SurePack into an email gateway or a document management system using the API, automatically encrypting outgoing files that meet certain criteria.

In summary, SurePack's innovation is offering military-grade security with consumer-grade simplicity. It eliminates the historical trade-off between security and convenience:

  • No passwords or shared secret setup needed – public keys are fetched by alias.
  • No complex key exchange for users – the server handles discovery, akin to how Signal or WhatsApp fetches keys from a server to initiate secure chats.
  • No user mistakes like forgetting to encrypt or using the wrong key – the client app takes care of it and even signs everything to prevent human error.
  • Anonymity option – unique among enterprise solutions, giving users control over how much identity to reveal.

Market Opportunity and Timing

The timing for SurePack is ideal. Secure file transfer is a growing market and a pain point for many organizations. Multiple independent analyses show this market is already multi-billion dollar in size and rising steadily. For example, one report estimates the global secure file transfer market at $2.4 billion in 2024 and projects it to reach about $3.7 billion by 2033. Another study projects an even faster growth trajectory – from ~$2.3 billion in 2023 to over $5 billion by 2033 (8%+ CAGR). This growth is driven by the urgent need for data protection across all industries. As digital transformation and remote work expand the exchange of sensitive data, companies are investing in secure transfer solutions "to avoid data breaches and comply with privacy laws".

Importantly, regulatory pressures are increasing. Laws like the EU's GDPR, California's CCPA, HIPAA in healthcare, and Australia's own Privacy Act demand strict safeguarding of personal data in transit. Companies face heavy fines and legal penalties for exposing customer or confidential information. (GDPR, for instance, allows fines up to 4% of global turnover for serious violations.) According to market research, the rollout of privacy regulations worldwide has pushed organizations to prioritize secure file transfer methods to remain compliant. In Australia, the government passed the Cyber Security Act 2024, the first cybersecurity-specific law, signaling a regulatory push for better cyber hygiene. Businesses that proactively secure their file exchanges will not only avoid penalties but also build trust with clients who are increasingly concerned about privacy.

Additionally, high-profile data breaches and espionage cases have made cybersecurity a boardroom issue. Executives now recognize that insecure file sharing (e.g. emailing unencrypted spreadsheets or using personal Dropbox accounts) is a liability. In a recent survey, 68% of U.S. employees admitted to saving or deleting company information from IM apps on their own, outside of official IT control – behavior that could lead to compliance nightmares. Organizations are actively seeking solutions that lock down file sharing without disrupting workflow. SurePack fits this need perfectly: it gives employees an easy tool that actually enhances security without forcing them to jump through hoops. By embracing a solution like SurePack, a company can mitigate the human factor in data leaks (often cited as the weakest link in security) while enabling productivity.

On the technology front, the need for post-quantum encryption is emerging as a strategic concern. Government agencies and large enterprises are already planning upgrades to their cryptography, fearing a "harvest now, decrypt later" scenario where adversaries steal encrypted data today to decrypt in a decade. NIST's standardization of algorithms like Kyber in 2024 is a clear green light: organizations are expected to start integrating PQC into products immediately. In fact, global tech players have started doing so – e.g., Cloudflare's data shows significant adoption of PQC in web traffic. This is a key timing advantage for SurePack: we are delivering a solution that is quantum-resilient from day one. This can attract forward-looking customers (finance, government, defense, critical infrastructure) who are mandated to achieve quantum safety in the near term. It also future-proofs our product, giving it a longer market lifespan and differentiation against older solutions.

In short, the confluence of market demand, regulatory drivers, and technological transition creates a perfect storm that SurePack is positioned to capitalize on:

  • Large Market, Clear Need: Organizations big and small need to send files securely; existing options are inadequate or too complex.
  • Growing Spend: Cybersecurity spending is rising globally each year – secure communications are part of that budget. We only need a slice of this growing pie.
  • Management Awareness: Cyber risk is now a C-suite and board concern, meaning willingness to invest in robust solutions is higher than ever (no longer an afterthought or just an "IT problem").
  • Lack of Easy Alternatives: No mainstream product today offers the blend of anonymity, ease, and strong encryption that SurePack does. We would enter as one of the few modern options in a space dominated by legacy approaches.

Competitive Advantages

SurePack stands out against both legacy solutions and current competitors:

In summary, SurePack combines the security experts have long desired with the usability that end users actually need. As one cryptography professor noted, there is "so much potential in this area and so many opportunities to do better... it's time to stop looking backwards". SurePack is that better, forward-looking solution – delivering secure file sharing that is robust, easy, and ready for the threats of tomorrow.

Execution Plan and Why We're Ready

Our team has not only envisioned this product – we've built it. The heavy R&D lifting (architecture design, cryptographic implementation, and prototyping) is already done and validated in action. We have a working codebase for both client and server. In fact, a reference implementation is live at publickeyserver.org, demonstrating the technology in real-world conditions. This significantly de-risks the project: we are not asking for a leap of faith on unproven tech, but rather to productize and launch what we've already proven to work.

Key development milestones already achieved:

With the core built, what remains is largely polish, packaging, and go-to-market execution – areas where an investment can accelerate success:

From an investment perspective, this is a compelling proposal because much of the technical risk has been retired by the work already completed. The funds would primarily fuel hardening the product and scaling it to market, rather than blue-sky research. Essentially, we have a Formula 1 engine built and tested – now we need to put it in a sleek car and hit the track with a marketing strategy. Our small size (<50 staff) is actually an advantage here: we can move fast and innovate without bureaucratic drag. Yet we also have the credibility of being a publicly listed ASX company, which can reassure enterprise customers that we're stable and accountable (something an open-source hobby project cannot as easily claim).

Conclusion: A Timely Opportunity for Innovation and Growth

In conclusion, SurePack represents a unique opportunity for our company to launch a cutting-edge cybersecurity product at the exact moment the world needs it. It addresses a clear and growing pain point with a solution that is technically advanced but user-centric. All the trends – remote collaboration, stricter privacy laws, rising cyberattacks, the coming post-quantum revolution – point toward a surging demand for exactly this kind of secure file sharing capability.

We have in our hands a working, innovative platform that outshines legacy solutions (as evidenced by expert criticisms of those tools) and offers concrete, fact-based advantages. Our approach is backed by defensible stats and standards: global surveys show the need for better security practices, market research shows organizations are investing more in secure file transfer, and government bodies like NIST are urging immediate adoption of the very cryptography we've built in. This gives us powerful talking points for customers and a head start on any competitors still playing catch-up.

For our company, investing in SurePack's productization and go-to-market is an opportunity to diversify and innovate with a solution that could generate new revenue streams. Given that we recently capitalized from a business sale and are actively looking for R&D investments, SurePack fits perfectly: it leverages our team's expertise, has global market potential, and could position us as leaders in a niche that aligns with the future of cybersecurity. The upside is significant – even capturing a small fraction of a multi-billion dollar market would yield substantial returns – and the downside is minimized by the progress already made.

Our boss may be a cynic, but the facts are on our side. Secure, anonymous, quantum-ready file sharing is not science fiction; it's running today in SurePack, and the world is asking for it. By supporting this initiative, we can transform a homegrown innovation into a commercial success that puts us at the forefront of secure communication technology. Let's seize this chance to turn SurePack into the next big product for our company – the right solution at the right time, with the right team to deliver it.

Sources:

© 2024 Public Key Server Project | GitHub Repository