Skip to content
Adversarial design

Engineered so no single compromise wins

No single compromise should decrypt a customer corpus, impersonate all organizations, rewrite history undetectably, or distribute a trusted malicious update. Each plane uses independent keys, controls, and recovery.

Adversaries

Who we design against

Malicious recipient

Legitimately receives a file, then attempts redistribution, forgery, or metadata stripping.

Insider / compromised admin

Holds valid credentials and attempts misuse, policy changes, or improper grants.

Ransomware operator

Compromises servers, encrypts storage, and exfiltrates databases and backups.

Ledger operator

Equivocates, omits events, serves stale checkpoints, or attempts correlation.

Supply-chain attacker

Targets source, dependencies, CI, build artifacts, or the update channel.

Bug-triggering attacker

Crafts hostile containers to exploit parsing, decompression, font, or image code.

Trust boundaries

Planes that never share one boundary

Billing, ledgers, trust registry, hosted ciphertext, authorization, updates, and recovery are separated by design.

Customer-controlled
  • Organization offline root
  • Alias-derivation secret
  • Customer HSM / KMS KEKs
  • Recovery quorum
Trust registry
  • Signed trust bundles
  • Ledger accreditation metadata
  • Product conformance metadata
  • No decryption secrets
Transparency
  • Primary ledgers
  • Read-only mirrors
  • Witness cosignatures
  • Optional public anchors
Authorization
  • Companion Agent
  • Identity provider
  • Device enrollment
  • Key Broker
Supply chain
  • Source control
  • Isolated CI
  • Threshold release signing
  • Update delivery
Resilience

Every compromise has a way back

Scoped blast radius

Compromising one server, key, ledger, or endpoint exposes a bounded, recoverable scope.

Detection paths

Witnesses, consistency proofs, and anomaly scoring surface equivocation and abuse.

Rotation paths

Signed epoch transitions rotate roots, aliases, and KEKs without erasing history.

Recovery procedures

Immutable backups, clean-room restores, and quorum recovery for every plane.

Attack paths

Threat → control → residual risk

A representative slice of the threat register that drives our automated tests and red-team exercises.

ThreatPrimary controlResidual risk
Stolen .osdf packageCiphertext + wrapped DEKMetadata leakage only
Hosted database dumpNo plaintext keys, tenant isolationAccount metadata exposure
Ransomware on serversImmutable backups, rebuildable infraRecoverable outage
Ledger split viewConsistency proofs, witness gossipTargeted clients if witnesses fail
Rollback to old revisionLive freshness, cached checkpointsOffline-only cannot guarantee newest
Malicious software updateTUF, threshold signing, transparencyQuorum or endpoint bypass
Transparency

See what we guarantee

The threat model pairs with our Claims Matrix - explicit about what is guaranteed, best-effort, and impossible.