SecureInfo
Talk to us

Your encryption is probably fine.
Your keys are the problem.

A patented method for key management, for software builders large and very small. An individual key for every item of content, never stored, split across separate systems so there is no single point anyone can compromise.

Talk to us
Patent granted in the US Granted in the United States.
UK, EU and Australia in their final stages.
Five years in production Not a prototype.
Version one has been running live since 2021.
Independently verified Verified through the Hartree National Centre for Digital Innovation, STFC.

The problem

Three fears. One cause.

Quantum computing, data breaches and legal jurisdiction look like three separate problems. They are the same problem wearing different clothes.

Quantum

Quantum computers do not break AES. NIST is explicit that AES-256 stays safe for a very long time. What quantum breaks is the asymmetric cryptography almost every system uses to wrap and exchange its keys. Your cipher is fine. Your key management is the exposed joint.

Breach

Attackers do not crack ciphertext. They find the keys. Where one platform key protects everything, a single theft opens the entire estate, including every historic backup you had forgotten about.

Sovereignty

Residency is where your data sits. Sovereignty is whose law binds whoever holds it. A legal order to your cloud provider is worthless if they cannot read your data. Governments do not take data from your cloud provider. They take it from whoever holds the key. Encryption on its own does not settle this.

Quantum computing and AI give attackers capabilities they have never had before. If your protected data sits in someone else's cloud, you need to know it stays safe there, and that control of it stays with you.

How it works

One key per item. Never stored. Never in one place.

Most security products are tools and building blocks. Holding a licence for them does not make a product secure, any more than owning a drill makes someone a carpenter. It depends entirely on how they are configured and used.
SecureInfo is the method, not another block.

one key key store content owner intermediate intermediate application

All but one would have to be compromised at the same moment.

  1. An individual key for every item Not one key per platform. Not one per tenant. One for every item or line of content you protect.
  2. Keys are never stored Content is rekeyed on every usage cycle. There is no key at rest for anyone to steal, and an old key is a useless key.
  3. No single point of compromise The credentials that unlock content are distributed across roughly five separate systems. All but one would have to be broken at the same moment.
  4. Control outside your cloud provider Key control sits outside the cloud platform and outside the application holding the data. No provider, in any jurisdiction, can produce plaintext it cannot read.
  5. Quantum-resistant where it matters The vulnerable joint in a conventional stack is the key exchange, not the cipher. Ours is built so that joint does not exist.

The successful approach to security is the one civilisation has used for a thousand years, with walls, moats and keeps: you build multiple defences, and you never let one partner or one shared mechanism be the thing everything rests on.

Why now

The deadline is already set, and it is not ours.

National Cyber Security Centre, part of GCHQ:
The post-quantum migration roadmap

2028Identify the cryptographic services needing upgrade and have a migration plan in place.
2031Execute high-priority upgrades.
2035Complete migration for all systems, services and products.

Large organisations have to plan for this, and they will push the requirement down their supply chains. The security questionnaires your customers send you are about to grow a post-quantum section, and it will ask how your keys are managed, how often they rotate and who can reach them.

Most software vendors have no answer. We are the answer you can give.

Three ways to use it

Bring your own tools, use ours, or mix the two.

Encryption

You keep your own key store and your own storage. We provide the encryption layer and the method that makes it work.

Encryption and keys

We handle key management under the distributed model. Your data never leaves your systems, and we never hold it.

Full service

Encryption, key management and storage together, with storage charged at cloud rates plus handling.

Available as a subscription, or as a technology licence for builders who want the method inside their own platform.

Where the boundary is

What this does not do.

Everyone in this market overclaims. We would rather tell you where the line is.

An attacker who compromises your application can still request whatever your application is authorised to request. Distributed keys narrow the window and make a single stolen credential worthless, but they do not stop someone operating as your own software.

What we do stop:

  • Stolen database dumps
  • Stolen and misplaced backups
  • Exposed storage buckets
  • Insiders with database access
  • Exfiltration ahead of ransomware
  • A government ordering your cloud provider to hand data over
  • Harvest-now-decrypt-later attacks that bank your ciphertext against a future quantum capability

Distributed keys stop most real breaches, and most real sovereignty risk.

Get in touch

Tell us what you are protecting.

We work with software builders of any size, from established vendors to one person writing code alone. If you are being asked questions about your key management that you cannot currently answer, that is exactly the conversation to have.

team@secureinfo.io