// the control plane for machine identity

Spent millions on security? Then answer these.

A GitHub Actions workflow deploys prod tonight. Did it prove it deserved that cloud token?No.
Your Terraform state holds your secrets in clear. Is it sealed to one machine?No.
Your next patient zero is a stolen session token. Can you stop it?No.
Your API key leaks tonight. Can you revoke it — and know it's truly dead?No.
Your cloud is certified sovereign. Can the CPU itself prove your secret stayed yours alone?No.

No proof. No privilege. Machine identity turns every "no" into "yes" — the step everyone skips, and the one we own.

// the simple version

Your cloud locks the building. We seal the drawer.

A sovereign cloud locks the building — certification, local operations, European law. Keep all of it. It protects everything around your secret.

We add the final layer inside: each secret sealed to the one machine that owns it, proven by the CPU itself — the highest root of trust there is. It lives in encrypted memory, readable by that machine alone — even the cloud's own hypervisor sees nothing. Not against your cloud. On top of it. That is machine identity — and it's what makes "sovereign" complete.

// where you're exposed today

Three holes you can't close today.

You can't revoke

NIS2 and DORA require you to cut access on demand. When an identity is a copyable string, the copy keeps working — you never truly revoked it. On paper, you're not in control.

You can't prove it

They demand evidence of who held what, and when. A shared, copyable secret leaves no trail. You can't show control you don't have.

You're personally on the line

The liability lands on the people in the room — up to €10M or 2% of global turnover. "We tried" is not a defence.

// every "no" above — turned to "yes"

Nine places we turn the "no" into "yes."

CI/CD · GitHub Actions
Your deploy workflow holds a long-lived cloud key. Anyone who copies it deploys as you — from anywhere.
No stored key. A short token is earned — repo, workflow, runner and runtime prove themselves first. Drift → refused.
Terraform state · no encryption
Your state file sits in a bucket with default encryption. Anyone with read on the bucket gets your secrets in clear.
Wrap it in a key that releases only into your attested machine. Off that machine, the state stays sealed.
Terraform state · cloud KMS
The key is in an HSM — good. But any role with decrypt opens it. A leaked runner, a stolen role — your state in clear.
We add a second factor: the machine's silicon identity. Your IAM stays. Now you must be the attested machine too.
The API key
Can you revoke your API key right now — and know it's truly dead, everywhere?
Bound to one machine, revocable in one click. With BYOK you hold it — we never do.
Read-only audit access
You grant an auditor read access with a service-account key — copyable. Leaked once, it works from anywhere.
Access released only into an attested collector, proven by its CPU. Off that enclave, refused. You revoke anytime.
Your provider's moves
Did your provider's tooling touch your secret? Do you have a log? No.
Every access in a signed, tamper-evident trail. You see — and prove — who touched what.
Sovereign, completed
Your cloud badge certifies the building. The last mile — who can actually read the secret inside — still needs proof.
Your secret lives in encrypted RAM, sealed to your machine by the CPU — a proven hardware root of trust. Readable by that machine alone, invisible to everyone else. The badge certifies the cloud. The silicon certifies you.
Patient zero · session token
A stolen session token today just works from the attacker's laptop.
The session is bound to the machine. Lifted elsewhere, useless. Drift kills it in real time.
Quick win · AD + PAW
Your admins sign in from anywhere. One stolen admin credential is full domain control.
Privileged access only from an attested PAW. Off that machine, the credential is dead.
// how it works — in plain words

Prove. Govern. Revoke.

1 · It proves it's itself

Every machine and agent proves, continuously, it's the real one — impossible to fake or copy, impossible to clone elsewhere.

2 · The secret can't hide

Your key is released only into a machine that's proven itself — and with your own key, we never even hold it.

3 · Revoke and prove, instantly

Drift, clone or doubt? Access dies in real time — and your auditor gets a signed, unbreakable trail.

// proven for real — not a slide

Receipts, not promises.

Real silicon

End-to-end live-proven on real AMD SEV-SNP and Intel TDX confidential VMs — GitHub Actions → Terraform → secret release, gated on the hardware quote itself. Not a diagram.

Sovereign root

Every decision is signed by a European GCP Cloud HSM root — the private key never leaves the HSM.

A third party can check it

The signed Release Permit lets an outside verifier confirm "this attested machine authorized this exact artifact" — offline, without trusting us.

Revocation, proven

Clone or drift a machine and its live session dies in real time — proven end-to-end on real silicon: 389 ms from drift to a locked account, the kill signed by the HSM root.

0secrets stored in your CI pipeline
2TEEs proven on real hardware — SEV-SNP + TDX
0custody — BYOK, we never hold your key
389 msdrift → access dead, measured on real silicon
Built on / proven with
AMD SEV-SNP
Intel TDX
vTPM measured-boot
GCP Cloud HSM
GitHub OIDC + WIF→STS
Terraform plan/apply binding
CAEP / SSF revocation
// we don't rip out your stack

Keep your providers. We harden them — then walk you to sovereign.

Reinforce

Keep Gemini, OpenAI, Stripe, your cloud. We wrap the identity around them. Nothing to migrate.

Keep

No rip-and-replace. Your stack stays — every machine just has to prove who it is.

Walk you to sovereign

Then we move you to full European sovereignty at your pace. Your call on the speed.

Proven for real, on real hardware — not a slide. European, and built to sit under SecNumCloud, not beside it.

// the waiting list

Name your riskiest key.

We onboard a few teams per quarter. Each pilot is a paid proof of value — skin in the game, both sides. Tell us what you'd secure first.

// you're on the list
We onboard a few teams per quarter, in order. We'll reach out — from a real person, not a funnel.