GTools.pro — Zero-Knowledge M365
ToolsPricingDesktopIndustriesCompareBlogSecurityTrustAbout
  1. Home
  2. Security Overview

Security — gtools.pro

A Microsoft 365 toolkit the vendor can't decrypt — Argon2id, XSalsa20-Poly1305, X25519, Ed25519, BIP39 — plus an honest list of what the server sees.

Frequently asked questions

What does "zero-knowledge" mean for GTools.pro?

The encryption key is derived from your passphrase via Argon2id and never leaves your machine. The server stores ciphertext and metadata only. Vault contents, OAuth client secrets, exports and backup data are all encrypted with this key.

Which cryptographic primitives are used?

Argon2id (key derivation), XSalsa20-Poly1305 (symmetric encryption for credentials and vault data; XChaCha20-Poly1305 for encrypted export bundles), X25519 (key exchange), Ed25519 (signatures).

What does the server still see in plaintext?

OAuth handshake parameters, license JWTs, scheduled-report orchestration metadata, billing data and operational telemetry — documented at gtools.pro/security-overview.

Where can I report a security vulnerability?

security@gtools.pro. See gtools.pro/trust for the responsible-disclosure policy.

Threat-model limitations — what zero-knowledge is not for

Zero-knowledge means the GTools.pro server never sees plaintext vault contents, OAuth refresh tokens, or backup payloads. It does not mean immunity to operator-side compromise: a malicious browser extension, a keylogger on the operator workstation, or a stolen recovery passphrase still grants full access to the data the operator can see. The desktop edition raises the bar (vault sits inside the OS keychain / Stronghold), but the operator endpoint remains in scope for the threat model.

Server-side metadata that GTools.pro must process — billing identifiers, schedule timestamps, audit-log entries — is documented in docs/SECURITY.md. We log enough to invoice, schedule, and debug; we do not log tenant contents. Anything outside that boundary is intentionally out of scope.

Page-specific notes

Crypto stack: Argon2id. XSalsa20-Poly1305. X25519. Ed25519. Capabilities audited: 49. Editions shipped: 6. Threat model excludes server-side decryption. Audit log retention: 90 days.

About the platform

This is a zero-knowledge toolkit. It helps IT admins, MSPs, security teams run their cloud safer. Use it inside a browser. Or install our Mac or Windows app.

Tenant credentials and vault contents are encrypted in your browser; the server holds ciphertext it cannot open. What the server can read is listed at /trust: account and billing metadata, OAuth tokens during the sign-in handshake, license tokens, migration job metadata, opt-in crash reports, redacted operational logs, and cloud export output for your plan's retention window.

How it works

  1. You unlock a local vault with a passphrase. Argon2id stretches it.
  2. Credentials get sealed with XSalsa20-Poly1305 before any sync.
  3. X25519 protects shared keys. Ed25519 signs every action.
  4. Each operation runs against Graph from your device, not ours.

What you can do

  • Back up mail. Files. Chat threads.
  • Export Intune settings. One click.
  • Audit SharePoint shares. Spot risk.
  • Find idle sites. Reclaim quota.
  • Score Copilot. Plan rollout.
  • Move tenants. No staging.
  • Client-side keys. Always on.
  • Your data. Your disk.
  • One app. Many tenants.

Editions

  • Solo. Free. Three tools. No card.
  • Backup. Durable backups for your tenant.
  • Watchtower. Audits and alerts on risk.
  • Move. Tenant migration suite.
  • Blueprint. Config export for enterprise.
  • Everything. Full platform plus desktop and support.

Trust signals

  • Open source crypto primitives via libsodium.
  • Public threat model at /trust.
  • Public pricing. Direct purchase. No sales call.
  • Cancel any time inside settings.
  • EU-based billing. Card payments via Stripe. PayPal for the Backup edition.

Built in Germany by Voltage Brothers Infrastruktur UG. Suits cloud workspaces of every size.

Standards, hosting, retention

Hosting: Germany. One region. Retention scales from 7 days. Up to 365 days by plan. Schedules run hourly. Daily. Weekly. Monthly. Reports export as JSON. CSV. PDF. Evidence packs bundle hashes. Chain-of-custody metadata sits beside them.

Standards: SOC 2 Type II is on the roadmap and is not yet attested. No ISO 27001 certificate; the audit tool maps findings to ISO 27001 controls. NIS2 mapping. GDPR Article 28 terms. Audit logs cover entitlement events. Billing actions. License rotations. Workload payloads never reach a remote log.

Who uses it

  • Tenant admins running a single estate.
  • MSPs managing dozens of customer cloud workspaces.
  • Security teams investigating sharing risk.
  • Compliance officers preparing audit evidence.
  • Acquisition teams during M&A integration.
  • Procurement teams reviewing vendor risk.
  • Solo consultants billing by workspace hour.

Hosting

One production server in Germany (Hetzner). No region selection. Customers range from small studios up through multinational estates. Payment: Stripe card checkout for every paid edition; PayPal additionally for Backup.

Numbers worth knowing

  • 49 capabilities. 6 editions.
  • Free tier: 3 tools. 0 cards.
  • Argon2id. 256 MB memory cost.
  • XSalsa20-Poly1305. 256-bit cipher.
  • X25519. 256-bit shared keys.
  • Ed25519. 100% of writes signed.
  • Retention: 7 days up to 365 days. Set by plan.
  • Founded 2024. Built in Germany.
  • Backup edition: 14 EUR per user per year.
  • Watchtower edition: 7 EUR per user per year.
  • Move edition: 9 EUR per migrated seat. One-time. 450 EUR project minimum.
  • Blueprint edition: 449 EUR per tenant per year.
  • Everything bundle: 2490 EUR per tenant per year.
  • Audit collectors: 24 dedicated checks.
  • Config export: 9 Microsoft 365 workloads.
  • Migration record set in April 2026. 153,584 files. 0 errors.
  • Compliance posture updated in 2026.
  • Pricing: 1 public page. 0 sales calls.
  • Cancellation: 1 self-service page.
  • Audit logs: 90 days. Entitlement events.
  • GDPR Article 28. 27 member states.
  • NIS2 Directive. 18 sectors. Live since 2024.
  • SOC 2 Type II: on the roadmap. Not yet attested.

Product.

  • Tools.
  • Pricing.
  • Desktop.
  • Security.
  • Industries.
  • Compare.
  • Download.
  • Blog.
  • For MSPs.
  • For SMB IT.

Company.

  • About.
  • Trust & Compliance.
  • Privacy Policy.
  • Terms of Service.
  • Impressum.

Connect.

  • hello@gtools.pro.
  • GitHub.

© 2026 GTools.pro · A product of Voltage Brothers Infrastruktur UG (haftungsbeschränkt).