This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
What I Built
I built DriveVault AI — a Zero-Knowledge, open-source file security vault powered by AES-256-GCM, Argon2id key derivation, and the open-weight Gemma AI model.
The Problem It Solves
Many of my friends and colleagues rely heavily on cloud storage services like Google Drive to back up sensitive documents (financial statements, tax records, identification documents, and private code). However, uploading unencrypted files to cloud storage exposes them to potential data breaches, unauthorized access, and third-party scanning. Existing encryption tools can be complex to configure or lack natural interaction.
DriveVault AI solves this by providing:
- Zero-Knowledge Encryption: Files are encrypted locally using authenticated AES-256-GCM with keys derived using Argon2id before ever hitting Google Drive. Plaintext never leaves the machine.
-
Gemma AI Assistant: An integrated natural language assistant powered by Google's open-weight Gemma model (
gemma-2-9b-it) that helps users query, organize, and manage their encrypted vault files through conversational commands. - Offline Local Storage Fallback: If offline or if Google OAuth credentials are absent, the application gracefully operates in Local Vault Mode.
Demo
Watch the full video demonstration of DriveVault AI in action:
▶️ YouTube Video Link: https://youtu.be/7WaD0XNAb3Y
Code
Check out the complete open-source codebase on GitHub:
🔗 GitHub Repository: https://github.com/paiikarthik/DriveVault-AI
How I Built It
DriveVault AI is built with a modern Python & FastAPI backend, cryptographic primitives, Google Drive API v3, and open-weight AI:
Architecture & Components
-
Cryptographic Layer (
CryptoVault):- Uses Argon2id (memory cost: 64MB, 3 iterations) for memory-hard password key derivation.
- Encrypts payloads using AES-256-GCM for authenticated encryption with nonces to protect against tampering.
- Packs files into custom
.vaultbinary packages containing magic header validation.
-
Open-Weight AI Assistant (
GemmaVaultAssistant):- Built using Google's Gemma open-weight LLM (
gemma-2-9b-it) via thegoogle-genaiSDK. - Understands natural language requests (e.g., "Show my encrypted files", "How does encryption work?", "Encrypt my resume") and guides users through security operations.
- Built using Google's Gemma open-weight LLM (
-
Google Drive Service (
GoogleDriveService):- Uses minimal scope authorization (
https://www.googleapis.com/auth/drive.file) to read and write only files created by DriveVault AI inside a dedicatedDriveVaultcloud folder. - Features automatic token refresh and PKCE flow handling for OAuth authentication.
- Uses minimal scope authorization (
-
Web UI Frontend:
- Clean HTML5, CSS3, and vanilla JavaScript interface with drag-and-drop file packaging, interactive password strength indicators, and direct file restoring.
-
Why Does Open Innovation Matter?
Open innovation is essential when building security and privacy-first software:
- Security Through Auditability: In cryptographic applications, security through obscurity fails. Open-source innovation allows the global developer community to audit encryption logic (AES-256-GCM + Argon2id), verify that plaintext data is never transmitted, and ensure no hidden telemetry exists.
- Open-Weight AI Sovereignty: Proprietary closed-source AI APIs pose privacy risks when dealing with metadata about user vaults. Using open-weight models like Gemma ensures AI capabilities can run locally or in self-hosted environments without sending sensitive operational data to third-party closed platforms.
- No Vendor Lock-In: Open protocols allow users to maintain full control over their master keys and backup files independently of any single proprietary platform.
My Agent Session
This project was developed and refined using Google's Antigravity AI Agent, demonstrating pair programming, automated test verification, and full-stack integration.
Prize Categories
- Best Use of Gemma (Primary Category)
<!-- Team Submissions: Please pick one member to publish the submission and credit teammates by listing their DEV usernames directly in the body of the post. -->
<!-- Thanks for participating! -->

Top comments (0)