hiVault — under development, coming soon

Sovereign secrets management for European businesses.

hiVault stores keys, passwords and certificates in encrypted form, protected by a master key that is never kept ready on the server, on infrastructure in the European Union and outside United States jurisdiction.

01

The master key is never stored ready for use

The key protecting your data is never stored whole in any location. It is reconstructed only at runtime in a deliberate unsealing ceremony and divided among trusted people.

02

Outside United States jurisdiction

Infrastructure in Europe. Your secrets are not subject to United States data access laws. Sovereignty is an architectural decision, not a declaration.

03

Security from the ground up

Encryption at rest and in transit, least privilege and mutual authentication for connections. No error passes unnoticed.

Deliberate security

How hiVault protects your master key

Access to secrets requires people to work together. The server never holds everything it needs to decrypt the data on its own.

  1. 01

    The master encryption key (MEK) is divided using Shamir's Secret Sharing. A defined threshold of shares is required; one share reveals nothing.

  2. 02

    Each share is encrypted with a separate password and stored independently, outside the cloud.

  3. 03

    Unsealing is a deliberate human ceremony, not an automatic read from a file.

  4. 04

    After a restart, the server is sealed again. Data remains unavailable until authorised people unseal it.

Designed for accountable organisations

For organisations that know where convenience ends and control begins.