Infrastructure access shouldn't mean
data access.
ASTIS is a cryptographic trust layer that separates plaintext, keys, access, and audit — so cloud, AI, vendors, and infrastructure can operate without reading business-payload plaintext.
Download the Company Overview (PDF) — one page, send it to your security team ↓
Operating infrastructure ≠ reading plaintext
Systems may need to store, route, process, or audit work. They don't need business-payload plaintext to do it.
ASTIS cryptographic trust layer
Control plane — not a plaintext data path
Your control
Plaintext stays here
Users, apps, workloads, and agents. Keys and policy decisions stay under your control.
Operational systems
Cloud · databases · AI
vendors · operators
Can store, route, automate, and operate — cannot read business plaintext.
Operational access ≠ plaintext access.
Business-payload plaintext does not flow through ASTIS — only protected artifacts and cryptographic control signals do.
Why this holds
Storage, encryption, access, and audit are separate trust boundaries — a breach of one does not automatically collapse the others.
The full picture — what each part of ASTIS receives
| Category | What ASTIS receives | Where plaintext lives |
|---|---|---|
| Business payload — emails, documents, application fields, secrets | Nothing — encrypted client-side, never sent to ASTIS | Only your client endpoint / workload |
| Encrypted SKEY capsules | Capsule + routing metadata | Transiently during approved rewrap — sKey (Mail onboarding) or CVS (organization workflows) |
| Managed CVS key material & workload DEKs | Sealed key material | Transiently in CVS memory during approved operations |
| HYOK CVS — private key custody | No private key material — your OpenPGP private key stays in your CVS (SKEY capsules still live in ASTIS, encrypted to your key) | Decryption authority on your infrastructure only |
| WKD (Web Key Directory) | Public keys + directory mapping | Contains no private keys |
| Account & control plane | Account, org, config, billing metadata | Operator plane (no business payload) |
| Audit | Security event metadata | No business-payload plaintext |
| Hosted MCP (dev-time) | Inputs you explicitly pass | No runtime crypto |
Business payload — emails, documents, application fields, secrets
What ASTIS receives
Nothing — encrypted client-side, never sent to ASTIS
Where plaintext lives
Only your client endpoint / workload
Encrypted SKEY capsules
What ASTIS receives
Capsule + routing metadata
Where plaintext lives
Transiently during approved rewrap — sKey (Mail onboarding) or CVS (organization workflows)
Managed CVS key material & workload DEKs
What ASTIS receives
Sealed key material
Where plaintext lives
Transiently in CVS memory during approved operations
HYOK CVS — private key custody
What ASTIS receives
No private key material — your OpenPGP private key stays in your CVS (SKEY capsules still live in ASTIS, encrypted to your key)
Where plaintext lives
Decryption authority on your infrastructure only
WKD (Web Key Directory)
What ASTIS receives
Public keys + directory mapping
Where plaintext lives
Contains no private keys
Account & control plane
What ASTIS receives
Account, org, config, billing metadata
Where plaintext lives
Operator plane (no business payload)
Audit
What ASTIS receives
Security event metadata
Where plaintext lives
No business-payload plaintext
Hosted MCP (dev-time)
What ASTIS receives
Inputs you explicitly pass
Where plaintext lives
No runtime crypto
ASTIS never holds it transient, in memory, managed plans only operator/metadata plane
Beyond access control
Zero Trust verifies access. ASTIS limits exposure.
Zero Trust verifies who can reach a system. ASTIS controls what that system, vendor, workload, or agent can actually see. Infrastructure operators, cloud services, AI tools, and automation do their job without receiving business-payload plaintext.
One trust layer — multiple integration paths
APIs · SDKs · workload-bound secrets · workflow/YAML · MCP · HYOK key custody
Regain control over sensitive data across cloud, on-prem, and hybrid environments — products, workloads, vendors, AI tools, and operators work without becoming plaintext holders. Infrastructure can operate; sensitive data stays under your control.
COMMUNICATE
ASTIS Mail
Secure communication alongside Gmail and Microsoft 365 — no migration. Message content stays encrypted; keys and access policy are separated from mailbox storage. TTL limits long-term exposure.
BUILD WITH APIs / SDKs
ASTIS API Platform
Use APIs and SDKs to add sealed-envelope encryption, hash-only sign/verify (a 32-byte digest, never the file), FPE/tokenization, key capsules, policy checks, and tamper-evident audit to your own product — regulated-data controls without building crypto yourself.
PROTECT WORKLOADS
Workload Secrets
Adds the runtime boundary Vault/KMS does not provide. Vault/KMS governs custody and release to authorized clients; ASTIS binds plaintext release to the attested workload — decrypted only inside that workload, in RAM, at use time. Cluster admins, etcd backups, CI logs, vendors, and cluster-read agents get ciphertext.
OWN KEY CUSTODY
HYOK CVS
Keys and decryption authority stay in customer-controlled infrastructure. ASTIS coordinates cryptographic workflows without holding plaintext or key authority. HSM support; EU/EEA, US, or customer-hosted residency by agreement.
the same controls exposed to agents over MCP — sign, verify, tokenize, and request sealed operations without business plaintext in model context, unless runtime access is explicitly granted. Learn more →
Built for regulated data
NIS2 · DORA · HIPAA · GDPR · AI governance
NIS2 / DORA
Essential entities (energy, transport, health, water, digital infrastructure, public administration), financial institutions, and ICT third-party risk programs: supplier, cloud, operator, and infrastructure plaintext exposure reduced by architecture.
HIPAA / Healthcare
Providers, payers, and business associates handling PHI: HIPAA-aligned workflows with customer-controlled keys and audit evidence; BAA available for Enterprise/HYOK. No HIPAA certification claimed.
GDPR / AI governance
Art. 32 encryption support, TTL-bounded data minimisation, audit evidence, and regional deployment options including EU/EEA managed data plane and HYOK. Sensitive plaintext stays out of model context unless runtime access is explicitly granted.
Don't take trust on faith
You don't have to trust us — verify it yourself.
Verifiable signatures
Every release is signed via the same /v1/sign API and verified with gpg — no ASTIS account. You verify it yourself.
Verify it yourselfLive workload checks
Workload secrets proven end-to-end, backed by 1,912 api-gateway + BFF tests green in CI.
See it workNo plaintext at the edge
Business payload is encrypted on your side; the edge sees a capsule and a proof, never plaintext.
How the boundary holdsHonest boundary
Internal dogfood + independently verifiable artifacts — not yet a third-party audit. EU/EEA data plane.
Trust CenterNumbers are shown only where they are independently verifiable or live on a see-it-work page. Full architecture is reviewable under NDA.
Pricing
Two product lines, separately priced. Buy one, the other, or both — billed under one organization.
Packaged workspace
ASTIS Mail
Solo $179/year · Team $15/seat/mo · Organization $20/seat/mo · Enterprise from $25k/year
- •End-to-end encrypted mail and calendar
- •Industry templates (legal hold, medical referral, HR severance)
- •Customer-controlled encryption keys
- •Optional Gmail and Outlook integration
Annual platform license
ASTIS API platform
Pro $15k · Business $60k · Enterprise from $150k · Strategic from $1M · HYOK CVS (self-hosted) from $50k
- •Sealed envelope, sign / verify, FPE, audit chain
- •ASTIS-managed CVS or HYOK (self-hosted) key custody
- •Annual, feature-gated tiers sized to your workload
- •EU-hosted infrastructure
Using an AI coding agent? Connect ASTIS MCP →
Self-hosted HYOK CVS contracts are sales-led only.
See API pricing for details.
Enterprise and sovereignty contracts in the EU are with ASTIS OÜ (Estonia), activated by invoice with bank transfer or card. The contracting entity and payment method for each plan are confirmed at checkout or in your Order Form.
Frequently asked questions
Mail product, API platform, and how the two fit together.
Keep plaintext where it belongs.
Talk to ASTIS about Mail, Platform, or self-hosted custody — or verify the proof yourself first.
Self-serve: Mail free trial · free developer access — see the two paths above.