Your cloud provider
Stores and processes your encrypted data and calls out to Alcazarix for key operations. It never holds, sees, or caches your master keys, and it cannot decrypt your data without the custodian honoring a key request under your policy.
Alcazarix custodians
Generate, store, and govern keys inside HSM-backed infrastructure. They perform key operations under the access policies you define, and log every operation. Your data never transits Alcazarix systems.
You
Own your keys and the policies that govern them. You approve access, monitor usage through audit logs, and can suspend or revoke key access at any time — instantly rendering cloud-held data unreadable.
Across jurisdictions
European custody is operated end to end by Alcazarix Europe B.V. under Dutch and German jurisdiction. North American custody is operated by Alcazarix, Inc. from Canada. Neither entity operates the other's custody infrastructure.