Trusted software acceptance environment
Test the software before you pay.
A sealed room in Stockholm checks the seller's delivery against your contract, on your data, and stamps PASS or FAIL.
For EU buyers of non-EU software.
No run yet. Run the sealed sample sends a real request to the room, which answers in about 10 seconds.
What your browser checks
Each check runs here, on your machine, not on our word.
- ·The room got exactly the package you sent.The room's fingerprint of the locked package is compared with the one your browser makes.
- ·The room opened exactly the sealed data.Its fingerprint of what it read is compared with the one this page kept back.
- Only the sealed room could open it.NextAn AWS hardware signature on every receipt, checked here.
- This receipt cannot be changed later.NextEvery receipt signed by the room and chained to the one before.
Security brief for your procurement team →Want your seller checked like this? Email them an invite or
Can we check your delivery in a sealed room before we pay? Hi, Before we accept and pay for the delivery, we would like it checked against our agreed clauses in Aarloven's sealed room in Stockholm. Our data stays sealed: only the room can open it, and we both get the same PASS or FAIL receipt. It takes 10 seconds to see how it works: https://aarloven.com Could we set this up for the next delivery?Technical details, and how to check it yourself
The room's answer
- Status
- No run yet.
Check it yourself
curl -sO https://aarloven.com/samples/sealed-sample.json jq -r .Envelope.ct_b64 sealed-sample.json | base64 -d | shasum -a 256 curl -s https://aarloven.com/v1/receipt -H 'content-type: application/json' --data-binary @sealed-sample.json
The second line must print the room's H_ciphertext. With your own package you keep the fingerprint of your data to yourself, so the room can only match it by opening the package.
Three steps, one receipt.
You and the seller agree on the clauses first. The room then settles them on your real data, without either side having to trust the other.
-
Seal
Your data is locked with a key that only the room's code can use.
Key held in AWS KMS, released only to the room.
-
Test
The seller's delivery runs against your clauses, inside a sealed room in Stockholm.
AWS Nitro Enclave: no operator can look inside.
-
Receipt
You get PASS or FAIL for each clause. The workspace is wiped; the receipt stays.
Use it to accept the delivery, or to dispute it.
Selling into the EU? Pass before they ask.
EU buyers worry about where their data goes and whether your release does what the contract says. Check it in the room first, then attach the receipt to your offer.
- The buyer's data is only ever opened inside the EU
- Your release is judged on the clauses you both agreed
- A PASS they can check without taking your word for it
Pay per delivery, not per seat.
Cheaper than paying for a delivery that does not work, and far cheaper than a data-transfer fine.
Sample
Free
as often as you like- The sealed sample, run live
- The same checks as a real run
Pilot
Per delivery
price agreed before the test- Your clauses, your data
- The room in Stockholm (EU)
- Receipts you can check yourself
Your own key Next
Per month
for teams that hold the key- The key lives in your AWS account
- Every unlock shows in your own logs
- Revoke it at any time
Book a pilot.
Tell us what is being bought and from whom. We reply by email to set up one delivery check.
What is true today, and what comes next.
Today
- The room runs in Stockholm (EU)
- The key is released only to the room (AWS KMS)
- A changed package is refused
- Fingerprint check in your browser
- Every unlock logged by AWS CloudTrail
Next
- AWS hardware signature on each receipt
- Signed, chained receipts
- Published room code
- Your own key
- Measured false-pass rate
How each of these was checked: the security brief →