Deploy on your VPS, bare metal, local network, or onion-only stack.
Compare
Secure intake without the portal, drive, or suite.
Dropbox, Google Forms, Nextcloud, Proton, OnionShare, and SecureDrop each cover part of the territory. Sprag's argument is the combination: sovereign hosting, one-way intake, no sender account, optional server-blind post-quantum E2E, optional Tor ingress, and evidence records in one small product.
USP stack
One intake box. Six constraints at once.
Competitors often do one or two of these well. Sprag is for the moments where dropping sovereignty from the intake path changes the risk profile.
Sovereignty
Easy intake without routing files through US Big Tech.
Sprag is not a SaaS inbox. It is software you run, so the file path can stay on infrastructure, storage, and jurisdictions you choose.
Point uploads at local MinIO, an EU S3-compatible provider, or another storage backend you control.
Keep sensitive intake out of Dropbox, Google Drive, AWS S3, or other US hyperscaler storage when those vendors are not acceptable.
Sprag USP
The advantage is not one feature. It is the stack.
Generic file requests can receive files. Secure drives can share files. Tor tools can hide a network path. Sprag puts the intake constraints together, keeps the product small, and leaves the infrastructure decision with the operator.
No workspace leaks back to the sender.
Uploaders get a page for sending files. They do not get a folder, listing, account, sync client, or download path.
Outsiders can send without joining anything.
Useful for clients, sources, employees, applicants, and partners who should not be pulled into your internal platform.
Ciphertext can arrive before the server sees content.
In E2E-required mode, the browser encrypts content and metadata with Sprag's ML-KEM-1024 plus P-384 hybrid profile before upload.
The same intake shape can run onion-only.
Operators can publish an onion service for cases where uploaders should not connect to a clearnet host directly.
Intake facts survive the upload.
Receipts, submission envelopes, hashes, manifests, and sealed-page records support later explanation without becoming case management.
The intake path belongs to you.
Run Sprag on infrastructure and storage you choose. Dropbox, Google Drive, and US hyperscaler storage are not required.
Competitor gaps
Adjacent tools prove why Sprag exists.
The comparison is not "can this tool receive a file?" The comparison is whether it keeps the whole sensitive-intake boundary intact.
US cloud file request
Dropbox File Requests
What it covers: Collects files from people into a Dropbox folder, including from uploaders who do not have a Dropbox account.
Sovereignty note: Dropbox says it may store, process, and transmit data in the United States and worldwide. Dropbox, Inc. acts as service provider for North America.
Gap for Sprag's job: It still belongs to a US cloud-drive account and folder model. Sprag makes intake the whole product: self-hosted, one-way, optionally post-quantum E2E/onion, with operator records.
Sprag edge: Choose Sprag when sensitive intake should not inherit Dropbox workspace or US-cloud assumptions.
US Big Tech form
Google Forms file upload
What it covers: Adds file upload to structured forms and stores uploaded files in Google Drive.
Sovereignty note: Google says information may be processed outside your country; Google LLC and wholly owned US subsidiaries are covered by its data-transfer certification.
Gap for Sprag's job: Google's own docs say file-upload responders need to sign in to a Google Account. Sprag is built for accountless outsiders and operator-chosen infrastructure.
Sprag edge: Choose Sprag when identity friction and US Big Tech data paths are the things you are trying to remove.
German self-hosted suite
Nextcloud File Drop
What it covers: Lets anonymous uploaders add files to a Nextcloud folder without seeing the directory contents.
Sovereignty note: Nextcloud has a strong sovereignty story when you already run the stack yourself; the company is Nextcloud GmbH in Germany.
Gap for Sprag's job: It is a file-drop mode inside a broader collaboration suite. Sprag concentrates the surface around intake pages, expiry, PINs, post-quantum E2E mode, Tor mode, receipts, and evidence.
Sprag edge: Choose Sprag when secure intake should be a small dedicated system, not a side feature of the file workplace.
Encrypted cloud sharing
Proton Drive sharing
What it covers: Provides encrypted cloud file sharing by email or link, with passwords, expiry, and no Proton account required for download.
Sovereignty note: Proton AG is domiciled in Geneva and governed by Swiss law. That is good cloud jurisdiction; it is still Proton's cloud.
Gap for Sprag's job: That is strong outbound sharing. Sprag is inbound intake: outsiders send files in, leave, and the operator keeps the host, storage, and submission records.
Sprag edge: Choose Sprag when the workflow starts with a third party sending sensitive files to infrastructure you control.
Tor ad-hoc drop
OnionShare Receive
What it covers: Runs a Tor onion receive service so people can submit files and messages directly to your computer.
Sovereignty note: OnionShare is not a cloud company; it is an open-source tool that runs locally and uses Tor.
Gap for Sprag's job: OnionShare is a strong ad-hoc handoff tool. Sprag turns anonymous intake into an always-on service with admin pages, operator-chosen object storage, receipts, and deployment modes.
Sprag edge: Choose Sprag when the anonymous drop needs to fit an operational workflow.
Whistleblower system
SecureDrop
What it covers: Gives media organizations and NGOs a full open-source whistleblower submission system for anonymous sources.
Sovereignty note: SecureDrop is a project of Freedom of the Press Foundation, a US 501(c)(3); deployed SecureDrop servers are owned by the installing organization.
Gap for Sprag's job: SecureDrop is a larger source program with operational security expectations. Sprag is the smaller one-way intake box: no source mailbox, no dialogue surface, no newsroom program required.
Sprag edge: Choose Sprag when the SecureDrop threat model is directionally relevant but the job is just controlled file intake.
Where Sprag wins
Use Sprag when intake itself is the risk boundary.
Sovereign intake outside US Big Tech
The operator needs file intake under its own host, storage provider, and jurisdiction choices. Run Sprag with local or non-US S3-compatible storage; US cloud services are optional, not required.Law firm client document intake
Clients can send PDFs and evidence without joining a portal or seeing a shared folder. Matter-specific upload pages, receipts, optional post-quantum E2E, and admin-side handling records.HR investigations and sensitive employee submissions
The sender should not become a collaborator, ticket participant, or drive user. One-way pages, expiry/PIN controls, submission envelopes, and a narrow return path.Journalist or researcher file drops without a full source platform
Sometimes the required workflow is file intake, not ongoing anonymous messaging. Accountless upload, Tor option, post-quantum E2E option, and no source mailbox to maintain.Self-hosted anonymous intake
Operators may need onion ingress and server-blind storage without deploying a collaboration suite. Plain HTTPS, E2E-required, and onion-only modes are the same product shape.Compliance evidence intake
The useful artifact is not a chat thread. It is what arrived, when, under which page, and how it was handled. Receipts, grouped submissions, hashes, manifests, and sealed-page framing.Decision axes
The questions that make Sprag look different.
| Axis | Sprag position | Why it matters |
|---|---|---|
| Sender burden | No account, no app, no workspace, no portal. | The sender's job is to submit material and leave. |
| Return path | No listing, folder, retrieval, sync, or shared context. | One-way intake avoids accidentally creating a collaboration surface. |
| Data sovereignty | You choose the host, region, and S3-compatible storage. | No Dropbox, Google Drive, or US hyperscaler has to sit in the intake path. |
| Host trust | Plain mode for simplicity; post-quantum E2E-required mode for ciphertext-only storage. | The same product can move from easy deployment to server-blind intake. |
| Network privacy | HTTPS, E2E-required, or onion-only deployment modes. | Operators can harden the channel without switching products. |
| After-the-fact explanation | Receipts, submission envelopes, hashes, manifests, and sealed pages. | Professional intake needs records, not a full case-management system. |
Sharp boundary
Sprag is not trying to replace every adjacent tool.
Use another tool when
- You need shared folders, sync drives, or collaborative editing.
- You need a survey builder with structured form analytics.
- You need encrypted outbound sharing from a cloud drive.
- You need a full whistleblower communication program.
- You are comfortable routing sensitive intake through a US cloud suite.
Use Sprag when
- Outsiders need to send files without becoming platform users.
- The upload channel must not expose a return browsing surface.
- You want storage, region, and provider sovereignty.
- You may need server-blind post-quantum E2E or onion-only intake.
- The operator needs receipts and records around what arrived.