Encryption you can verify, not just trust.
Your team holds the keys. Our staff cannot see your files. Every action is tamper-proof and signed. The whole security model is public, and we use the same code paths internally that you do.
Pick how strict you want to be. Per workspace, per folder.
End-to-end is the strictest setting. Server-side keeps more features running. Either way, no one at Corvault can read your files unless you specifically approve it.
Files are encrypted on your device before upload. Corvault never sees plaintext. Share links are disabled.
Encrypted at rest with platform-managed keys. Full feature set including share links, approvals, and previews.
No standing access. Ever.
Every interaction between Corvault staff and customer data passes through an approval loop. There is no second path, no break-glass back channel — even our CEO uses the same flow.
How we handle the keys.
The simplest way to say our threat model: we assume someone hostile is on every team, including ours. The system has to hold even then.
One key per workspace
Each workspace has its own encryption key, so a problem in one never reaches another. Older keys stay around so older files still open, but new files are always written with the freshest key.
Rotate whenever you want
An owner can rotate a workspace key on demand. The rotation runs on your device: we re-distribute sealed copies to your members but never see the key itself. Older keys stay wrapped so older files keep opening, and the rotation is recorded in your audit log.
We are key-blind
The server moves opaque ciphertext between your members — sealed workspace keys, wrapped private keys — and never holds a workspace content key or a private key in the clear. That is a property of the protocol, not a policy we promise to follow.
Devices, sessions, anomalies — surfaced and acknowledgeable.
- Every session is listed and revocable
Each sign-in is tracked server-side with its device and location, and you can kill any of them instantly. Refresh tokens rotate on every use, so a stolen one works at most once and the theft shows up as a reuse attempt.
- 2FA that resists phishing
Passkeys (Face ID, Touch ID, security keys) are preferred. Authenticator apps work too. SMS codes are off by default — they're too easy to intercept.
- Catches impossible logins
A session that jumps continents in 10 minutes is paused, and your admins are notified.
- Sensitive actions ask again
Mass downloads, role changes, and key changes require a fresh 2FA prompt — even in the middle of an active session.
Run it on your own servers.
Run a Corvault server inside your own network. Every byte stays within your boundary, while the app keeps updating from us automatically. Same product, your jurisdiction.
- Signed and verifiable. every package is cryptographically signed; you check what you install.
- Your bytes never leave. file traffic goes straight between your users and your own server on your network; the central service only holds metadata and coordination.
- You choose the jurisdiction. the server runs where you put it, so data residency is a decision you make about your own hardware rather than a region we offer.
Audit-ready paperwork, audit-ready architecture.
The two halves of compliance — controls in production, and proof on paper — wired together.
Security that actually ships with your product.
30-day free trial. Full Business plan. Cancel anytime before billing.