The master key is never stored ready for use
The key protecting your data is never stored whole in any location. It is reconstructed only at runtime in a deliberate unsealing ceremony and divided among trusted people.
hiVault — under development, coming soon
hiVault stores keys, passwords and certificates in encrypted form, protected by a master key that is never kept ready on the server, on infrastructure in the European Union and outside United States jurisdiction.
The key protecting your data is never stored whole in any location. It is reconstructed only at runtime in a deliberate unsealing ceremony and divided among trusted people.
Infrastructure in Europe. Your secrets are not subject to United States data access laws. Sovereignty is an architectural decision, not a declaration.
Encryption at rest and in transit, least privilege and mutual authentication for connections. No error passes unnoticed.
Deliberate security
Access to secrets requires people to work together. The server never holds everything it needs to decrypt the data on its own.
The master encryption key (MEK) is divided using Shamir's Secret Sharing. A defined threshold of shares is required; one share reveals nothing.
Each share is encrypted with a separate password and stored independently, outside the cloud.
Unsealing is a deliberate human ceremony, not an automatic read from a file.
After a restart, the server is sealed again. Data remains unavailable until authorised people unseal it.
Designed for accountable organisations
Early access
hiVault is currently under development. Leave your contact details and we will let you know about our progress and opportunities to take part in the first deployments.
MVP under development — access is not yet for sale.