For business
You set the rules. We secure them.
Protect anything — for your AI agents, customers, employees, or partners. You decide who and what can open it; we keep it encrypted, verifiable, and yours.
Encrypted on your infrastructure terms — verifiable, and the keys stay yours.
- You hold the keys — we only ever store ciphertext
- Proven, audited cryptography — never hand-rolled
- You govern every access — people and AI agents alike
One platform, every relationship
Govern what gets shared — and with whom.
Same encrypted core underneath. Deploy once; extend to every use case.
Built for the agent era
Your AI agent acts — without seeing your secrets
It asks, you approve, the value routes from your vault to the page — around the agent. Every step is audited.
Deployment
Run it your way
Choose the model that fits your security posture and ops team. All three run the same encryption engine.
Managed cloud
We run the infrastructure in a region you select. Your data is sealed before it leaves your environment — we store ciphertext only. Fastest to get started; no servers to maintain.
Your own cloud / VPC
Deploy into your AWS, GCP, or Azure environment using our container images. You control the network boundary, the keys, and where data lands. We provide setup docs and can assist with the rollout.
Self-hosted containers
Run entirely on your own hardware or air-gapped environment. No external dependency at runtime. You own the deployment end-to-end; we provide the images, docs, and an agreed support channel.
Security & trust
Built to be checked
Audited crates, no hand-rolled crypto — your security team can verify every layer.
Independently verifiable
Run it in your own environment and confirm the behavior; the same .rbx opens in the browser and the CLI.
Audited crates, no hand-rolled crypto
XChaCha20-Poly1305 · Argon2id · HKDF-SHA-256.
Every access is audited
A verifiable trail your security team can review.
Contact sales
Talk to an expert
Tell us what you need to protect — for your AI agents, customers, employees, or partners. We'll scope a plan around your security, compliance, and deployment needs.
We store only what you send us, to reply — no trackers.
Or email us directly: sales@secretbox.example
Questions
What teams actually ask.
No. Files and fields are sealed on your device before they reach us. We store only ciphertext we have no way to read — not by policy, but because we never receive the key. Recovery is Shamir-split across people you designate, so even that path doesn't involve us.
You control recovery. When you seal something, you can split the key using Shamir's Secret Sharing and give shares to designated trustees. Any threshold of those trustees — say 3 of 5 — can recover access together, with no single person (and no one at Secret Box) holding enough alone. If a key holder leaves, you rotate through the recovery flow.
Agents connect through our MCP server and can see item labels to do their job — they never receive a value. When an agent requests a fill or send, your policy resolves it: deny, ask for approval, or allow. You approve each action; every step is written to your audit log.
The engine uses audited crates (XChaCha20-Poly1305, Argon2id, HKDF-SHA-256, Shamir) and no hand-rolled cryptography. Your security team can run it in your own environment, verify its behavior, and review the append-only audit trail. We do not currently hold SOC 2 or ISO 27001 certifications — if that is a hard requirement, talk to us about your timeline.
Three paths: managed cloud (we run it), your own cloud or VPC (you run it with your own keys), or self-hosted containers (full control, air-gapped if needed). Talk to us about which fits your environment.
On the managed cloud, data is stored in the region you select at setup. For VPC and self-hosted deployments, you choose the location entirely — we don't touch it.
Not in the current release. We are building it — talk to us about your identity provider and timeline, and we can scope it into your deployment.