Cryptographic standards you can verify.
For enterprise perimeters, trust demands proof. Here is the full cryptographic stack behind the Fortress of Sovereignty — published for independent review, not asserted on faith.
Every layer of the perimeter is documented with its algorithm, key strength, and the zero-knowledge guarantee that accompanies it. No proprietary secrecy, no hidden key escrow.
Standards & commitments, at a glance
The cryptographic primitives and privacy guarantees your auditors will ask about — surfaced as badges for quick verification by enterprise security and procurement teams.
Key management lifecycle
Local generation
All keys are generated on your device using a cryptographically secure random source. The platform never participates in key creation.
Zero-knowledge custody
Keys are derived and held client-side. We never possess, escrow, or transmit a decryption key — so we cannot decrypt your data even under compulsion.
Rotation without re-upload
Key rotation re-encrypts vault objects in-place on your device. You never re-share plaintext to rotate credentials.
Recovery isolation
Your 24-word seed phrase is the sole recovery path. No support flow, admin token, or override can regenerate it — by design.
Our cryptographic design is published and open to independent peer review today. Independent attestation is underway on an annual cycle, not a one-time checkpoint.
Zero-knowledge audit
Cryptographic design published and open to independent peer review today.
SOC 2 Type II
Continuous controls monitoring with an annual independent attestation cycle underway.
Controls documentation
Type I controls documentation, encryption whitepaper and DPA available to enterprises under NDA.
Privacy is the architecture, not a setting.
- We collect the minimum metadata required to route and render your perimeter — and nothing more.
- Because we hold only ciphertext, a subpoena can compel us to hand over ciphertext we cannot read.
- We publish our cryptographic design for independent peer review rather than relying on proprietary secrecy.
- No advertising, no data brokering, no model training on your communications or stored content.
- Erasure is verifiable and complete — there is no plaintext shadow to purge because none ever existed.
Request the enterprise trust pack.
Our controls documentation, cryptographic whitepaper, and data-processing addendum are available to regulated-sector and enterprise teams under NDA.
Contact our trust team