Roadmap

Product roadmap

A practical view of where ZipPigeon is headed: stronger team controls for organizations, clearer deployment ownership, and safer expansion of the constrained anonymous sharing path.

Principles

ZipPigeon should stay narrow and understandable. The product is for private file handoffs, not broad cloud storage. Every roadmap item should make the sender, recipient, access window, encryption boundary, and remaining metadata easier to explain.

Enterprise brand and policy controls

Future enterprise plans include custom logo and theme support, branded recipient pages, organization policy controls, default expiration rules, allowed recipient patterns, download-limit policies, and clearer administrative reporting. These controls should help teams make private delivery feel like their own trusted process without weakening the encryption model.

Bring your own cloud storage and database

The planned enterprise deployment model should support customer-owned encrypted object storage and a customer-owned PostgreSQL-compatible database. That direction gives organizations more control over residency, backup, retention, and infrastructure review while keeping file contents protected in the browser before storage.

Anonymous one-time sharing

A constrained anonymous path is live for short-lived handoffs without creating an account. It uses browser encryption, a one-time share link, short expiration, low limits, blocked high-risk file types, and human verification where configured. It does not keep the transfer in a sender history or provide account-level audit records.

Security gates before higher limits

Anonymous sharing should not grow into an open upload pipe. Before increasing size or traffic limits, the roadmap calls for stronger human checks, edge rate limits, short retention, one-time download grants, file-type controls, browser-side file validation, monitoring, and abuse-response paths.

What remains future work

Enterprise SSO enforcement, formal compliance reports, customer-managed keys, public key transparency, hardware-backed server controls, and deeper privacy-preserving malware analysis remain future work. Public pages should keep naming these as planned or under evaluation until the controls are shipped and documented.

Frequently asked questions

Are enterprise controls available today?

This page describes future direction. Current public pages should not imply that custom branding, bring-your-own infrastructure, SSO enforcement, or formal compliance controls are already complete unless release notes say so.

Will bring-your-own storage make files readable to ZipPigeon?

No. The intended boundary remains browser encryption before upload. Bring-your-own storage changes infrastructure ownership, not the normal file-content privacy model.

Why include anonymous sharing?

Some people only need a short-lived encrypted handoff and should not have to create an account. The live flow stays deliberately limited so it does not replace account-bound delivery when records and identity matter.

Send the file. Keep control of the link.

Use ZipPigeon when a file needs to reach the right person without becoming another attachment or shared folder to clean up later.

Open signed-in sender