Skip to content
Zero-trust access controlComing soon

Controlled decryption bound to identity, device, and policy.

Sensitive files stay encrypted at rest and in transit. A Companion Agent, identity-provider authentication, enrolled device keys, optional endpoint posture, short-lived leases, and a Key Broker govern when plaintext is released - never with a universal master key.

  • Per-document envelope encryption
  • No bulk-decrypt endpoint, no master key
  • Short-lived, device-bound rendering leases

Enterprise

Zero-trust access control

Capabilities

What Enterprise does

Envelope encryption

Random per-document DEKs wrapped under customer-controlled KEKs.

Device keys

Hardware-backed, non-exportable keys in TPM or Secure Enclave.

Key Broker

Narrow, single-document unwrap grants - never bulk decryption.

Identity integrations

Microsoft Entra, Login.gov, PIV/CAC, OIDC, SAML, and Okta.

Companion Agent

Local policy enforcement, leases, heartbeats, and signed telemetry.

Endpoint posture

Normalized signals from CrowdStrike, Defender, SentinelOne, and Jamf.

Get started

The future of trusted documents

Bring cryptographic verification, verifiable provenance, and zero-trust access control to every document your organization creates and receives.