Engineered so no single compromise wins
No single compromise should decrypt a customer corpus, impersonate all organizations, rewrite history undetectably, or distribute a trusted malicious update. Each plane uses independent keys, controls, and recovery.
Who we design against
Malicious recipient
Legitimately receives a file, then attempts redistribution, forgery, or metadata stripping.
Insider / compromised admin
Holds valid credentials and attempts misuse, policy changes, or improper grants.
Ransomware operator
Compromises servers, encrypts storage, and exfiltrates databases and backups.
Ledger operator
Equivocates, omits events, serves stale checkpoints, or attempts correlation.
Supply-chain attacker
Targets source, dependencies, CI, build artifacts, or the update channel.
Bug-triggering attacker
Crafts hostile containers to exploit parsing, decompression, font, or image code.
Planes that never share one boundary
Billing, ledgers, trust registry, hosted ciphertext, authorization, updates, and recovery are separated by design.
- Organization offline root
- Alias-derivation secret
- Customer HSM / KMS KEKs
- Recovery quorum
- Signed trust bundles
- Ledger accreditation metadata
- Product conformance metadata
- No decryption secrets
- Primary ledgers
- Read-only mirrors
- Witness cosignatures
- Optional public anchors
- Companion Agent
- Identity provider
- Device enrollment
- Key Broker
- Source control
- Isolated CI
- Threshold release signing
- Update delivery
Every compromise has a way back
Scoped blast radius
Compromising one server, key, ledger, or endpoint exposes a bounded, recoverable scope.
Detection paths
Witnesses, consistency proofs, and anomaly scoring surface equivocation and abuse.
Rotation paths
Signed epoch transitions rotate roots, aliases, and KEKs without erasing history.
Recovery procedures
Immutable backups, clean-room restores, and quorum recovery for every plane.
Threat → control → residual risk
A representative slice of the threat register that drives our automated tests and red-team exercises.
| Threat | Primary control | Residual risk |
|---|---|---|
| Stolen .osdf package | Ciphertext + wrapped DEK | Metadata leakage only |
| Hosted database dump | No plaintext keys, tenant isolation | Account metadata exposure |
| Ransomware on servers | Immutable backups, rebuildable infra | Recoverable outage |
| Ledger split view | Consistency proofs, witness gossip | Targeted clients if witnesses fail |
| Rollback to old revision | Live freshness, cached checkpoints | Offline-only cannot guarantee newest |
| Malicious software update | TUF, threshold signing, transparency | Quorum or endpoint bypass |
See what we guarantee
The threat model pairs with our Claims Matrix - explicit about what is guaranteed, best-effort, and impossible.