The proof

Everyone promises security.
We prove it.

Three products on one foundation – and none of them asks you to take our word for it. Everything here can be verified with standard tools; we hand over the entry point in conversation.

Guaranteed by Math Zero Access Verify it yourself

The claim

“Your data is safe.”
How would you know?

Security is almost everywhere underwritten organisationally: by contracts, certificates, signatures and the operator's own account of itself. In the most recent attack on one of the world's largest package registries every one of those measures worked exactly as designed – and the attack still got through, because it used the trusted path itself. Four break points, and they are the same everywhere:

The signature“The package is signed.”
A signature proves the sender – not the content. Take over the publishing automation and you publish as “trusted”.
The trust anchor“The name is familiar.”
Trust anchors are overwritable. A familiar package name can quietly carry new content, and history can be rewritten.
The self-attestation“We logged the access.”
The operator attests to itself. Code, delivery and certificate of authenticity sit in one pair of hands – with full access to everything.
The detection“We noticed it.”
Detection comes after distribution. What happened in the hours before is forensics rather than a query – exactly when reporting deadlines are running.
SEFETOTrust by mathematics
A signature proves the sender. Provenance proves the content. That is precisely the difference the three products build in – sovereignty stops being a promise and becomes a property of the system.

Architecture

From building block to sovereign platform

Applications are placed on a sealed foundation – from the messenger through the code and package platform to your own application. What is built below, everything above inherits.

Applications & services

Sovereign communication SEFETO Chat Messenger, files and video calls
Sovereign supply chain SEFETO Registry An npm registry and an apt archive in one service
Sovereign Git hosting SEFETO Forge Git hosting with issues and pull requests
Re-platforming Your application Open slot – customer applications move onto the same foundation.

Every building block automatically inherits the sovereignty of the foundation.

Foundation

Sovereign zero-access foundation

Protocol layer · live

A sealed key space – guaranteed by mathematics rather than by assurance.

BFT consensus

A federation of independent machines holds the same state. Nothing is finalised until at least two thirds of the nodes arrive at exactly the same result – below that the system stops rather than forging.

Protocol layer · live

Threshold keys

The private key is created without any central party and split into shares – it never exists as a whole. Only a qualified majority acting together can sign or decrypt.

Protocol layer · live

Confidential computing

The memory of the running application is to be encrypted against the most privileged attacker imaginable as well – the administrator of the host system. Established, purchasable technology, but not part of operations today.

Hardware layer · product build-out

The two load-bearing pillars are built and running: the one layer that cannot be bought is the protocol layer. Confidential computing is the dashed pillar – established, purchasable hardware technology that is added as a product build-out during pilot operation and carries nothing today.

On EU operation: operating in the EU is a property of the product on offer; the publicly reachable installation runs on globally distributed nodes and stores nothing but ciphertext there. Access is ruled out because the operator – and with it the operator's jurisdiction – has no access to the execution layer.

The products

No concept, no prototype.

All three building blocks are running – what differs is how far commercialisation has come. That is why the maturity is stated on every block, so nobody has to guess.

Finished product · deployable today

SEFETO Chat

A messenger just like the ones you know – except only you can see it: one-to-one and group chat, end-to-end encrypted attachments and video calls in a single solution. Run on-premise or in a private cloud, white-labelled under your own brand on request.

Go to the product page
  • All three layers at once: content, metadata and jurisdiction are protected – conventional messengers encrypt the content only.
  • Files are part of it: large files, shared team spaces, versions and retention periods live in the same encrypted store – even the file names stay ciphertext.
  • Prepared for post-quantum: attackers record traffic today in order to open it later. The algorithms in use can be migrated to the forthcoming post-quantum standards – the architecture is prepared for that switch.
Live · publicly verifiable

SEFETO Registry

An npm registry and an apt archive in a single service – only tamper-proof. Every delivery carries a certificate of authenticity with a content checksum that customers, auditors and regulators can verify themselves, without having to take the operator's word for it.

Go to the product page
  • Adoption is a config entry: npm install and apt-get keep working unchanged; compliance evidence accrues as a by-product of normal work, not as a special project before the audit.
  • Tampering leaves traces: history is append-only – a familiar package name cannot quietly carry new content; a silent swap breaks the publicly verifiable chain.
  • What is still missing is stated too: confidentiality even from the operator is demonstrated for private packages; emitting the evidence in the common standard formats is the remaining step. A dedicated registry cannot yet be handed over in full.
Live · part of the same installation

SEFETO Forge

The matching Git hosting: object store, refs, packfiles, issues, pull requests and real smart HTTP – as a sealed service on the same installation as the registry. Code, release and delivery therefore sit in one chain that can be verified end to end. A Git instance can be handed over to the customer in full.

Go to the product page
  • Compatibility measured, not claimed: an unmodified git clone and git push work straight against it. Object IDs are checked against the git binary, and packfiles have to be accepted by git index-pack.
  • Certified delivery: every response carries a certificate against the network's root key; every pushed state a portable threshold signature, verifiable offline with standard tools.
  • Operator blindness: private repositories sit as ciphertext under blinded addresses; keys go to authorised identities only. The operator cannot read along – not even under a court order.

The evidence

Don't take our word for it.
Check it yourself.

The evidence does not rest on our word: five verification paths are documented for the supply chain, each carried out by the reviewer alone – without our involvement, once they have the entry point. In the apps the demonstration is built in: real queries against the running infrastructure, not slides.

Proof 01

“The operator cannot read.”

The stored state of the application contains ciphertext only; an access attempt from outside is refused by the system itself – demonstrated in the running application, not on a slide.

Proof 02

“What runs is exactly what we say runs.”

The running program code is compared by checksum against the released source state, bit-identical; source access and the guided reproducible build take place under NDA. And who may change the sealed containers at all is answered by the network itself, cryptographically certified.

Proof 03

“These bytes, from this source, unchanged.”

Fetch a package with unmodified npm, recompute the supplied checksum locally and hold it against the certificate of authenticity. Two minutes from your own terminal, without asking us.

Your next step

Five minutes of live proof

The proof is running – but deliberately not as a link on this page. Which entry point is the right one depends on what you want to check, so we demonstrate it in conversation. No test accounts with prepared content, no guided sequence, no mock-ups – you click freely.