Client-side envelope encryption
AES-256-GCM symmetric encryption executes in browser memory or local SDK before any packet traverses the network boundary.
Share files only the recipient can open. Cryptographically enforced zero-knowledge architecture: encryption and decryption keys are derived entirely client-side. The server stores only ciphertext and provides immutable audit verification receipts.
Engineered for banking secrets, regulatory filings, Board communications, and air-gapped infrastructure.
AES-256-GCM symmetric encryption executes in browser memory or local SDK before any packet traverses the network boundary.
Every download request generates a signed Ed25519 receipt proving who opened the envelope and at what exact timestamp.
Define exact expiration timestamps down to the second. Ephemeral payloads are permanently purged once the threshold arrives.
Embeds invisible cryptographic watermarks identifying the authorized viewer on PDF, image, and tabular documents.
Revoke access to shared documents instantly, preventing any future decryption even if the link has already been opened.
Full alignment with Indonesian personal data protection law (UU PDP No. 27/2022) and OJK banking confidentiality standards.
Verified cryptographic parameters evaluated for enterprise compliance.
| Standard component | Algorithm standard | Key size / Mode | Compliance status |
|---|---|---|---|
| Payload encryption | AES-GCM (Authenticated) | 256-bit symmetric | FIPS 140-3 compliant |
| Public key agreement | X25519 / ECDH | 256-bit Curve25519 | RFC 7748 standard |
| Digital signatures & receipts | Ed25519 | 256-bit Edwards curve | RFC 8032 verified |
| Key derivation function | Argon2id / PBKDF2-HMAC-SHA256 | 64 MB memory / 3 iterations | OWASP Recommended |
Sample API interaction when an enterprise sends an encrypted file envelope.