Supi Drive
A company cloud drive with encrypted storage
The backend for a private file-storage product. Large uploads, encrypted files, previews generated in the background, and administration for a company's employees.

The challenge
A company that wants its own file storage, instead of a consumer cloud drive, needs three things to be right from the start: files must be protected at rest, large uploads must not fall over, and browsing a folder with thousands of items must stay fast.
The requirement
- Folders and files with the operations people expect: move, rename, search, trash and restore.
- Uploads of any size, straight from the client to storage.
- Thumbnails for images, video and PDFs.
- Per-user storage quotas.
- An administrator who can invite employees, set quotas and suspend accounts.
- Files encrypted in storage.
The solution
The API covers accounts and invitations, a folder tree, and file handling. Folder listings mix folders and files in one cursor-paginated response. Moves are checked so a folder can never end up inside itself. Deleting a folder soft-deletes everything beneath it, and restoring brings it all back.
Files do not pass through the API server. The client asks for signed URLs and uploads directly to object storage, in a batch for many small files or in parts for a large one, with an endpoint to abandon an upload cleanly.
Each file gets a thumbnail and a BlurHash placeholder, so the interface can show a soft preview immediately.
Administrators invite, list and manage employees, and each account carries a storage quota.
Architecture
The API is a NestJS application on PostgreSQL through Prisma.
Encryption. Each user has their own data key, which is itself stored encrypted under a server key. File contents are encrypted with the user’s key. Compromising the storage bucket alone yields nothing readable.
Previews. Thumbnail generation is hybrid. Small images are processed inline so the preview is ready at once. Video and PDF work is pushed to a BullMQ queue and handled by a worker, with a dashboard for inspecting jobs.
Redis holds refresh tokens, administrator sessions, rate-limit counters and a short-lived cache of folder listings.
Authentication. Users have short-lived access tokens with rotating refresh tokens. Administrators use server-side sessions. Passwords are hashed with Argon2id, and authentication routes have a much stricter rate limit than the rest of the API.
Storage is any S3-compatible service; development runs against a local equivalent in Docker.
Technology
NestJS, TypeScript, PostgreSQL, Prisma, Redis, BullMQ, the AWS S3 SDK, Argon2, sharp and FFmpeg for media processing.
Outcome
The first two phases of the backend are complete and deployed: accounts, folders, encrypted file storage, large uploads, previews, search, trash and employee administration. Sharing and further administration features are planned for later phases.

