SecureInfo
Talk to us

Your encryption is probably fine.
Your keys are the problem.

Patented key management for software builders. An individual key for every item of content, never stored, split across separate systems so there is no single point anyone can compromise.

Talk to us
Patent granted in the US Granted in the United States. UK, EU and Australia in their final stages.
Five years in production Not a prototype. Version one has been running live since 2021.
Independently verified Verified through the Hartree National Centre for Digital Innovation, STFC.

The problem

Three fears. One cause.

Quantum computing, data breaches and legal jurisdiction look like three separate problems. They are the same problem wearing different clothes.

Quantum

Quantum computers do not break AES. NIST is explicit that AES-256 stays safe for a very long time. What quantum breaks is the asymmetric cryptography almost every system uses to wrap and exchange its keys. Your cipher is fine. Your key management is the exposed joint.

Breach

Attackers do not crack ciphertext. They find the keys. Where one platform key protects everything, a single theft opens the entire estate, including every historic backup you had forgotten about.

Sovereignty

Residency is where your data sits. Sovereignty is whose law binds whoever holds it. A legal order to your cloud provider is worthless if they cannot read your data. Governments do not take data from your cloud provider. They take it from whoever holds the key.

How it works

Take the key, break it into pieces, send the pieces to different corners of the world.

Most security products are tools and building blocks. Holding a licence for them does not make a product secure, any more than owning a drill makes someone a carpenter. It depends entirely on how they are configured and used. SecureInfo is the method, not another block.

  1. An individual key for every item Not one key per platform. Not one per tenant. One for every item or line of content you protect.
  2. Keys are never stored Content is rekeyed on every usage cycle. There is no key at rest for anyone to steal, and an old key is a useless key.
  3. No single point of compromise The credentials that unlock content are distributed across roughly five separate systems. All but one would have to be broken at the same moment.
  4. Control outside your cloud provider Key control sits outside the cloud platform and outside the application holding the data. No provider, in any jurisdiction, can produce plaintext it cannot read.
  5. Quantum-resistant where it matters The vulnerable joint in a conventional stack is the key exchange, not the cipher. Ours is built so that joint does not exist.
one key key store content owner intermediate intermediate application

All but one would have to be compromised at the same moment.

Why now

The deadline is already set, and it is not ours.

2028Identify the cryptographic services needing upgrade and have a migration plan in place.
2031Execute high-priority upgrades.
2035Complete migration for all systems, services and products.

National Cyber Security Centre, part of GCHQ — post-quantum migration roadmap

Large organisations have to plan for this, and they will push the requirement down their supply chains. The security questionnaires your customers send you are about to grow a post-quantum section, and it will ask how your keys are managed, how often they rotate and who can reach them. Most software vendors have no answer. We are the answer you can give.

Three ways to use it

Bring your own tools, use ours, or mix the two.

Encryption

You keep your own key store and your own storage. We provide the encryption layer and the method that makes it work.

Encryption and keys

We handle key management under the distributed model. Your data never leaves your systems, and we never hold it.

Full service

Encryption, key management and storage together, with storage charged at cloud rates plus handling.

Available as a subscription, or as a technology licence for builders who want the method inside their own platform.

Where the boundary is

What this does not do.

An attacker who compromises your application can still request whatever your application is authorised to request. Distributed keys narrow the window and make a single stolen credential worthless, but they do not stop someone operating as your own software.

What they do stop is stolen database dumps, stolen and misplaced backups, exposed storage buckets, insiders with database access, exfiltration ahead of ransomware, a government ordering your cloud provider to hand data over, and harvest-now-decrypt-later attacks that bank your ciphertext against a future quantum capability. That is most real breaches and most real sovereignty risk.

Everyone in this market overclaims. We would rather tell you where the line is.

Get in touch

Tell us what you are protecting.

We work with software builders of any size, from established vendors to one person writing code alone. If you are being asked questions about your key management that you cannot currently answer, that is exactly the conversation to have.

team@secureinfo.io