Trust & Custody

An operating model built for sovereignty

Anyone can promise that your cloud provider can't reach your keys. We'd rather show you the corporate and operational structure that makes it true — and let your counsel judge it.

The principle

No single company — and no single jurisdiction — should control both your encrypted data and the keys that unlock it. Your cloud provider holds data and never keys. Your key custodian holds keys and never data. Everything on this page exists to keep those two things in different hands.

Your cloud provider — AWS · Azure · Google Cloud

Holds your encrypted data. Never holds your keys.

Key operations via XKS · EKM · Managed HSM BYOK
United States

Alcazarix, Inc.

Platform engineering & North American custody

  • Develops the Alcazarix key management platform
  • Licenses the platform software to Alcazarix Europe B.V.
  • Operates North American key custody from data centers in Canada
  • Has no operational control over European infrastructure or key material
Netherlands

Alcazarix Europe B.V.

European operations & custody

  • Separately owned — not a subsidiary of and not controlled by Alcazarix, Inc.
  • Owns and operates the European infrastructure — servers, HSMs, and data center contracts in Germany
  • Independently deploys and operates the licensed platform, including updates
  • Employs European operations and customer support staff
  • Holds European key custody in German data centers
policy, approval, rotation, revocation

You

Own the keys. Define policy. Approve, rotate, and revoke at any time.

What each party can and cannot do

Your cloud provider

Stores and processes your encrypted data and calls out to Alcazarix for key operations. It never holds, sees, or caches your master keys, and it cannot decrypt your data without the custodian honoring a key request under your policy.

Alcazarix custodians

Generate, store, and govern keys inside HSM-backed infrastructure. They perform key operations under the access policies you define, and log every operation. Your data never transits Alcazarix systems.

You

Own your keys and the policies that govern them. You approve access, monitor usage through audit logs, and can suspend or revoke key access at any time — instantly rendering cloud-held data unreadable.

Across jurisdictions

European custody is operated end to end by Alcazarix Europe B.V. under Dutch and German jurisdiction. North American custody is operated by Alcazarix, Inc. from Canada. Neither entity operates the other's custody infrastructure.

A note on legal claims

This page describes Alcazarix's corporate and operational structure factually, so that your legal and security teams can perform their own analysis. It is not legal advice, and we deliberately avoid categorical claims about how any specific statute applies to this structure. A detailed custody dossier — covering entity ownership, contracts, and operational control — is available to your counsel under NDA.

Put this structure in front of your lawyers

Request the custody dossier, or bring your security architects to a working session with ours.

Request the custody dossier