06 / Trust & Compliance

Verifiable trust, by design.

A zero-knowledge perimeter is only as credible as the evidence behind it. Here is how we prove — not promise — that your data stays yours.

Compliance posture

We treat compliance as the output of architecture, not a layer bolted on. Because we never hold your keys, most regulatory burdens that other providers carry — key escrow, lawful-access risk, plaintext exposure — structurally cannot apply to us.

Independent audit roadmap

We are pursuing SOC 2 Type II attestation, with an annual independent third-party audit of our encryption, access control, and incident-response posture. Type I controls documentation is available to enterprise customers under NDA.

GDPR & CCPA aligned

We design for the strictest global privacy regimes. Data minimization, purpose limitation, and the right to erasure are defaults — and because we hold only ciphertext, erasure is verifiable and complete.

Geo-redundant residency

Encrypted replicas are stored across geographically separated, Tier III+ data centers. Enterprise customers can request regional confinement for sovereign data-residency requirements.

Coordinated disclosure

A responsible-disclosure program rewards researchers who report valid vulnerabilities. We publish remediation timelines and maintain a public changelog of security-relevant fixes.

Encryption attestation

All data is encrypted client-side with AES-256 before transit and at rest. We publish our cryptographic design — key derivation, transport, and rotation — so it can be independently reviewed.

Zero-knowledge architecture

Keys are derived and held on your device. We never possess, escrow, or transmit decryption keys, which means our compliance posture cannot degrade into key-handover under legal compulsion.

In progress

SOC 2 Type II

Continuous controls monitoring; annual attestation cycle underway.

Planned

ISO 27001

ISMS scope definition scheduled; targeted certification within 18 months.

Live

Zero-knowledge audit

Cryptographic design published and open to independent peer review today.

Request a trust pack

Enterprise and regulated-sector teams can request our controls documentation, encryption whitepaper, and data-processing addendum under NDA.

Contact our trust team

Report a vulnerability

Found a security issue? Report it through our coordinated-disclosure program. Valid reports are rewarded and remediated on a public timeline.

Submit a report

Build your Fortress of Sovereignty.

Single users, business teams and enterprise perimeters — the same non-bypassable security, scaled to your vault.