Security

Encryption you can verify, not just trust.

Your team holds the keys. Our staff cannot see your files. Every action is tamper-proof and signed. The whole security model is public, and we use the same code paths internally that you do.

Tamper-proof audit trailOpen security model
Time staff have spent inside your files
0 sec
unless you approve it
Workspace keys we are able to read
0
rotation runs on your device
How fast a share link goes dark
under 1 sec
globally, after revoke
Security audit events
hash-chained
append-only, tamper-evident
Encryption

Pick how strict you want to be. Per workspace, per folder.

End-to-end is the strictest setting. Server-side keeps more features running. Either way, no one at Corvault can read your files unless you specifically approve it.

End-to-end encryptionMaximum privacy
AES-256-GCM

Files are encrypted on your device before upload. Corvault never sees plaintext. Share links are disabled.

Server-side encryptionCollaboration mode
AES-256-GCM

Encrypted at rest with platform-managed keys. Full feature set including share links, approvals, and previews.

Zero-trust access

No standing access. Ever.

Every interaction between Corvault staff and customer data passes through an approval loop. There is no second path, no break-glass back channel — even our CEO uses the same flow.

STEP 01

Staff request

Any support action requires an explicit, time-limited request with a stated reason.

STEP 02

Customer approves

The customer sees exactly what will be accessed and approves or rejects in the app.

STEP 03

Audited & expires

Access is logged, stamped, and expires automatically — no manual revoke needed.

Keys

How we handle the keys.

The simplest way to say our threat model: we assume someone hostile is on every team, including ours. The system has to hold even then.

One key per workspace

Each workspace has its own encryption key, so a problem in one never reaches another. Older keys stay around so older files still open, but new files are always written with the freshest key.

Rotate whenever you want

An owner can rotate a workspace key on demand. The rotation runs on your device: we re-distribute sealed copies to your members but never see the key itself. Older keys stay wrapped so older files keep opening, and the rotation is recorded in your audit log.

We are key-blind

The server moves opaque ciphertext between your members — sealed workspace keys, wrapped private keys — and never holds a workspace content key or a private key in the clear. That is a property of the protocol, not a policy we promise to follow.

Session security

Devices, sessions, anomalies — surfaced and acknowledgeable.

Active sessions4 devices
MacBook Pro · M3This device
Brooklyn, NY · Active now
iPhone 16 Pro
Brooklyn, NY · 2 minutes ago
iPad Pro · M2
Brooklyn, NY · 3 hours ago
Windows 11 · EdgeUnusual
Berlin, DE · 1 day ago
  • Every session is listed and revocable

    Each sign-in is tracked server-side with its device and location, and you can kill any of them instantly. Refresh tokens rotate on every use, so a stolen one works at most once and the theft shows up as a reuse attempt.

  • 2FA that resists phishing

    Passkeys (Face ID, Touch ID, security keys) are preferred. Authenticator apps work too. SMS codes are off by default — they're too easy to intercept.

  • Catches impossible logins

    A session that jumps continents in 10 minutes is paused, and your admins are notified.

  • Sensitive actions ask again

    Mass downloads, role changes, and key changes require a fresh 2FA prompt — even in the middle of an active session.

Self-hosting

Run it on your own servers.

Run a Corvault server inside your own network. Every byte stays within your boundary, while the app keeps updating from us automatically. Same product, your jurisdiction.

  • Signed and verifiable. every package is cryptographically signed; you check what you install.
  • Your bytes never leave. file traffic goes straight between your users and your own server on your network; the central service only holds metadata and coordination.
  • You choose the jurisdiction. the server runs where you put it, so data residency is a decision you make about your own hardware rather than a region we offer.
Compliance posture

Audit-ready paperwork, audit-ready architecture.

The two halves of compliance — controls in production, and proof on paper — wired together.

GDPR
GDPR
EU data residency available
CCPA
CCPA
Subject access requests built-in
Get started

Security that actually ships with your product.

30-day free trial. Full Business plan. Cancel anytime before billing.