For business

You set the rules. We secure them.

Protect anything — for your AI agents, customers, employees, or partners. You decide who and what can open it; we keep it encrypted, verifiable, and yours.

Encrypted on your infrastructure terms — verifiable, and the keys stay yours.

Your company sits at the centre and defines one rule for who and what may open your protected data. From that rule, four secured channels reach out to the parties you work with — an AI agent, a customer, an employee, and a partner. Each channel passes through a small policy gate set by your rule, in the spirit of deny, then ask, then allow. The protected value travels each channel sealed as ciphertext and is never exposed, and a single check mark confirms every channel is verified. You set the rules; we keep it encrypted, verifiable, and yours.
  • You hold the keys — we only ever store ciphertext
  • Proven, audited cryptography — never hand-rolled
  • You govern every access — people and AI agents alike

Built for the agent era

Your AI agent acts — without seeing your secrets

It asks, you approve, the value routes from your vault to the page — around the agent. Every step is audited.

Diagram: an AI agent asks Secret Box to fill the card-number field. The value stays hidden from the agent. Policy resolves to ask; you approve; the value routes from the vault directly to the page, bypassing the agent; and an audit row records the action.

Deployment

Run it your way

Choose the model that fits your security posture and ops team. All three run the same encryption engine.

Managed cloud

We run the infrastructure in a region you select. Your data is sealed before it leaves your environment — we store ciphertext only. Fastest to get started; no servers to maintain.

Your own cloud / VPC

Deploy into your AWS, GCP, or Azure environment using our container images. You control the network boundary, the keys, and where data lands. We provide setup docs and can assist with the rollout.

Self-hosted containers

Run entirely on your own hardware or air-gapped environment. No external dependency at runtime. You own the deployment end-to-end; we provide the images, docs, and an agreed support channel.

Security & trust

Built to be checked

Audited crates, no hand-rolled crypto — your security team can verify every layer.

Independently verifiable

Run it in your own environment and confirm the behavior; the same .rbx opens in the browser and the CLI.

Audited crates, no hand-rolled crypto

XChaCha20-Poly1305 · Argon2id · HKDF-SHA-256.

Every access is audited

A verifiable trail your security team can review.

Contact sales

Talk to an expert

Tell us what you need to protect — for your AI agents, customers, employees, or partners. We'll scope a plan around your security, compliance, and deployment needs.

We store only what you send us, to reply — no trackers.

Or email us directly: sales@secretbox.example

Questions

What teams actually ask.

No. Files and fields are sealed on your device before they reach us. We store only ciphertext we have no way to read — not by policy, but because we never receive the key. Recovery is Shamir-split across people you designate, so even that path doesn't involve us.

You control recovery. When you seal something, you can split the key using Shamir's Secret Sharing and give shares to designated trustees. Any threshold of those trustees — say 3 of 5 — can recover access together, with no single person (and no one at Secret Box) holding enough alone. If a key holder leaves, you rotate through the recovery flow.

Agents connect through our MCP server and can see item labels to do their job — they never receive a value. When an agent requests a fill or send, your policy resolves it: deny, ask for approval, or allow. You approve each action; every step is written to your audit log.

The engine uses audited crates (XChaCha20-Poly1305, Argon2id, HKDF-SHA-256, Shamir) and no hand-rolled cryptography. Your security team can run it in your own environment, verify its behavior, and review the append-only audit trail. We do not currently hold SOC 2 or ISO 27001 certifications — if that is a hard requirement, talk to us about your timeline.

Three paths: managed cloud (we run it), your own cloud or VPC (you run it with your own keys), or self-hosted containers (full control, air-gapped if needed). Talk to us about which fits your environment.

On the managed cloud, data is stored in the region you select at setup. For VPC and self-hosted deployments, you choose the location entirely — we don't touch it.

Not in the current release. We are building it — talk to us about your identity provider and timeline, and we can scope it into your deployment.