Skip to content
SNDL/VAULT

Offline encrypted archive custody

Store now.Decrypt later.

We preserve encrypted archives beyond network reach, maintain their integrity, and perform bespoke authorized decryption when the hardware and economics are ready.

OFFLINE BY DEFAULTPhysically isolated custody
BESPOKE RECOVERYOn request, case by case
VERIFIED INTEGRITYHashes and custody records
CONTROLLED RELEASEAuthorized recipients only

01 / SERVICE

The archive survives. The attack surface does not.

Long-term encrypted data needs more than capacity. It needs media stewardship, cryptographic integrity and a recovery path designed before future compute makes decryption commonplace.

01A / CUSTODY

Offline cold storage

Customer-authorized encrypted archives are inventoried, hashed, copied to appropriate preservation media and held beyond routine network reach.

  • Secure physical or agreed encrypted intake
  • Redundant offline copies
  • Scheduled integrity verification
  • Media refresh and format migration
  • Documented chain of custody
01B / RECOVERY

Bespoke decryption

Every recovery engagement is assessed individually. There is no anonymous upload, instant cracking interface or shared public corpus.

  • Hardware and feasibility assessment
  • Customer-specific recovery plan
  • Isolated working environment
  • Milestone-based commercial proposal
  • Controlled plaintext release

02 / PROCESS

From sealed media to controlled recovery.

Qualify

Authority, archive, encryption, condition and objective.

Ingest

Inventory, hashes and custody manifest are established.

Preserve

Redundant copies remain isolated and periodically verified.

Assess

Hardware progress, methods, cost and probability are reviewed.

Recover

Approved work occurs in isolation; output is released securely.

03 / READINESS

“Later” is a technical decision—not a date on a calendar.

A recovery window depends on the encryption scheme, keyspace, implementation, available key material, archive value, target data and the cost curve of suitable hardware.

SIGNAL / 01

Cryptographic profile

Algorithm, mode, key derivation, implementation version and configuration determine which methods are plausible.

SIGNAL / 02

Recovery leverage

Known plaintext, partial credentials, damaged key stores, metadata and representative samples can change feasibility.

SIGNAL / 03

Compute economics

We compare probable workload with available hardware, energy, time, budget and the value of the target outcome.

04 / BOUNDARY

Future capability without future exposure.

THE SYSTEM IS DESIGNED TO CREATE

  • Verifiable archive integrity
  • Offline, access-controlled preservation
  • Documented authority and custody
  • Customer-specific recovery environments
  • Controlled delivery to approved recipients

THE SYSTEM IS NOT DESIGNED TO CREATE

  • A public archive of encrypted material
  • An anonymous decryption service
  • A searchable corpus of customer data
  • Unsupervised employee access
  • Automatic publication after recovery

05 / ENGAGEMENT

Every archive arrives with a different problem.

A / PRESERVE

Custody engagement

For organisations that need encrypted material preserved now with integrity evidence and a defined retrieval policy.

B / ASSESS

Feasibility engagement

For archive owners who need a technical and commercial view of whether recovery is practical today.

C / RECOVER

Decryption engagement

A bespoke statement of work covering authorized methods, infrastructure, milestones, custody and release.

DESCRIBE YOUR ARCHIVE →

Confidential qualification

Have an archive the present cannot open?

SUBMIT A DECRYPTION RFP →