Security brief · for your procurement and security team
Where your data goes, and who can open it.
One page with the answers a security review asks for first. Every claim says how it was checked, and the parts that are not done yet are marked Next.
1Where your data goes
Your data is locked in your browser's package, and it can only be opened inside a sealed room in Stockholm. Everything in between handles it locked.
- Cloudflare and our host only ever handle the locked package and the receipt, never your readable data.
- While the room works (about 10 seconds), the host keeps the locked package in a temporary file only its own account can read, and deletes it when the request ends.
- The room has no disk. The only files it writes live in its own memory and are deleted as each clause is checked, so nothing is kept after the request.
2Who can open it
Only the sealed room's own code. The key that opens your package lives in AWS KMS in Stockholm, and its policy refuses everyone else, our own administrators included.
The policy names the room by its code measurement (PCR0). AWS checks that measurement on every request, against a document signed by the room's hardware. The part that refuses everyone else:
"Sid": "NobodyDecryptsOutsideTheRoom",
"Effect": "Deny", "Principal": "*", "Action": "kms:Decrypt",
"Condition": { "StringNotEqualsIgnoreCase": {
"kms:RecipientAttestation:PCR0": "1cf5ef68cad1d985…6e62cb3f876973fa1f606da9b8729bdeb8c10f4d34b4" } }
✓ Checked 4 Oct 2026 An unlock attempt by our full-access administrator role was refused by AWS (AccessDeniedException), while the sealed sample still passed through the room.
Our administrators can still change the policy. AWS CloudTrail records any such change. Holding the key in your own AWS account removes even that. Next
3Every unlock, as AWS recorded it
AWS CloudTrail writes down every use of the room key. Here is that log, exported without addresses or names.
Unlocks of the room key
Unlock attempts AWS refused, in our account
- Unlocked by the sealed room
- Our setup tests, before the policy was final
- Refused by AWS
Exported from AWS CloudTrail by us on … (raw export). AWS does not name the key when it refuses, so refusals are counted for our whole account. Log files signed by AWS that you can check yourself: Next
4Where it runs
In AWS's Stockholm region (eu-north-1), Sweden, as an AWS Nitro Enclave: an isolated machine with no disk, no login and no network beyond the one channel from its host.
| Part | Where | How it was checked |
|---|---|---|
| The sealed room | AWS eu-north-1a, Stockholm | The running enclave reports code measurement 1cf5ef68…, the one the key policy requires. |
| The room key | AWS KMS, eu-north-1, single-region | Key metadata, read on 4 Oct 2026. |
| The website | Cloudflare's network | Serves pages; never sees readable data. |
| Pilot requests | Cloudflare D1, EU jurisdiction | The database is created with EU jurisdiction, so it is stored and run inside the EU. |
5What is kept, and for how long
| What | Kept | Details |
|---|---|---|
| Your sealed package | Only while the room works | A temporary file on the host, still locked, deleted when the request ends. |
| Your readable data | Never outside the room | Opened only inside the enclave, in memory. |
| The receipt | Sent to you | The verdict per clause, fingerprints of what was read, the model's hash. |
| A pilot request | 90 days | Only what you type in the form. Deleted after 90 days. |
| A waitlist sign-up | 365 days | Only your email, used once to say that "Your own key" is ready. |
| Page counts | A number per day | For example "sample runs: 12". No cookie, IP address or id is kept. |
Nothing you send is used to train a model. The judge is a small open model (Qwen2.5-0.5B, file hash 74a4da8c…) baked into the room; it does not learn from requests.
6Who processes it
| Company | What for | Sees readable data? |
|---|---|---|
| Amazon Web Services | The room (EC2 with Nitro Enclaves), the key (KMS), the unlock log (CloudTrail); Stockholm | No. The enclave is closed even to us, and the key opens only for the room. |
| Cloudflare | The website, the tunnel to Stockholm, pilot requests (D1, EU) | No. It forwards the locked package only. |
7How you can check, instead of trusting us
- Run the sealed sample, then change one byte. Your browser computes the fingerprints itself and compares them with the room's.
- Read two signed receipts and check their signatures and chain in your browser.
- Download the sample package from the homepage's technical details, and check its fingerprint with one command.
- An AWS hardware signature on every receipt, checked in your browser against AWS's own root certificate. The checker is written and tested; the room starts signing next. Next
Try that check now, on a real AWS-signed document
This document comes from a public test set (evervault, Apache-2.0), not from our room. Your browser checks it with the same code the receipts will use: AWS's root certificate, the certificate chain, and the hardware's signature.
8Questions from your security team
Send them with the pilot form, saying they are security questions. We answer in writing.