Tell your customers “we cannot read your data” — and mean it.
InvisiCloud lets B2B SaaS vendors truthfully remove themselves from their customers' data — without rearchitecting the product. Your customer (or a partner) holds the key; you just point your existing S3 client at a new endpoint.
Security questionnaire
“Can your staff access our uploaded files? Where are the encryption keys?”
We are cryptographically unable to read your data. The key stays with you; our infrastructure only ever handles encrypted payloads.
The stuck deal
A real deal is stalled in security review
When you sell into health, legal, HR, fintech, govtech, or supply-chain buyers, the security review decides the deal. The questions that stall it look like this:
“Can your staff access our data?”
“Where are the encryption keys held?”
“How do you handle Schrems II and international transfers?”
Rearchitecting for client-side encryption isn't an option — and today's alternatives don't answer the question:
Client-side encryption
Breaks sharing, presigned links, and product features — and forces you to rearchitect the application.
BYOK / SSE-KMS
Improves key control, but the cloud provider still encrypts the data and could reach the keys. Provider and vendor stay inside the trust boundary.
Confidential computing
A hardware and attestation project, not a storage answer — and not something you can ship this quarter.
Why InvisiCloud
Revenue enablement, not insurance
InvisiCloud is bought to win competitive RFPs and pass security questionnaires — not primarily as breach protection.
Win the deal
“We are cryptographically unable to read your data” becomes a differentiated, truthful line item in RFPs and security questionnaires — the answer that unblocks stalled enterprise and public-sector deals.
No rearchitecting
Works with the standard S3 SDKs — AWS SDK, boto3 — and your existing application code. Integration is a DNS/endpoint change plus running one stateless container. No client-side key management.
Sovereignty as tailwind
Supports GDPR data-protection-by-design and supplementary-measures strategies for international transfers. Keep your hyperscaler — remove it, and yourself, from the plaintext trust boundary.
How it works
Zero-trust storage, split across two independent parties
No single infrastructure operator — Gateway, Key Server, or storage backend — can decrypt customer object contents on its own.
Built on the patented TLSHare protocol and Secure Multi-Party Computation. The Key Server holds the TLS private key and KMS/HSM-backed master key but never sees payloads; the Gateway processes encrypted payloads but never holds keys. Neither party alone can reconstruct plaintext — data stays protected as long as both are not compromised at the same time.
Flagship use case
Confidential customer-document storage for B2B SaaS
Store the files your customers upload with the vendor and all infrastructure providers removed from plaintext access — while the product keeps behaving exactly as it does today.
User-uploaded documents
Contracts, patient records, HR files, case files — stored through your existing S3 code path, with you and every infrastructure provider cryptographically removed from plaintext access.
Sharing keeps working
Identity-based sharing and presigned links keep functioning — no second-channel key distribution, no client-side key management.
Revocation keeps working
Revoke access the way you do today. No long-term keys live on client devices.
Multi-backend redundancy
Connect one or two storage backends of your choice. Provider-independence and redundancy come built in.
Where this is going: the same two-party model extends toward confidential analytics (Apache Iceberg, PyIceberg) and confidential compute — future-facing directions we're building toward, not products available today.
The CISO questions
What a security team will ask
What we're honest about
InvisiCloud is early access and it is technical infrastructure — not a replacement for legal assessment, IAM, or organizational controls. Straight answers on the edges:
- Metadata — object names, sizes, access timing, IPs — remains visible.
- Authorized users or compromised credentials can still exfiltrate data they are allowed to access.
- The Key Server is security-critical for availability and access control, even though its compromise alone does not expose plaintext.
- No external cryptographic audit or academic review yet; performance testing is ongoing.
Scope your first deployment against a stuck deal
Get early access and we'll scope your first deployment on one bucket, one document workload — against a concrete deal in security review. We're onboarding early-access deployments now.