Cryptographic trust layer

Infrastructure access shouldn't mean data access.

ASTIS is a cryptographic trust layer that separates plaintext, keys, access, and audit — so cloud, AI, vendors, and infrastructure can operate without reading business-payload plaintext.

Download the Company Overview (PDF) — one page, send it to your security team ↓

Customer-controlled keys·HYOK key custody·EU/EEA data plane · regional options·Verifiable evidence
Built for teams facing GDPR, NIS2, DORA, HIPAA, data-sovereignty, and third-party-risk pressure.

Operating infrastructure ≠ reading plaintext

Systems may need to store, route, process, or audit work. They don't need business-payload plaintext to do it.

ASTIS cryptographic trust layer

Control plane — not a plaintext data path

Key coordinationSigningPolicyAudit evidence

Your control

Plaintext stays here

Users, apps, workloads, and agents. Keys and policy decisions stay under your control.

PlaintextCustomer-controlled keysPolicies
Plaintext boundaryOnly protected artifacts →Plaintext does not cross

Operational systems

Cloud · databases · AI vendors · operators

Can store, route, automate, and operate — cannot read business plaintext.

Protected artifacts path →Encrypted envelopesSignaturesFPE valuesAudit evidenceSealed secrets

Operational access plaintext access.

Business-payload plaintext does not flow through ASTIS — only protected artifacts and cryptographic control signals do.

Why this holds

Storage boundaryEncryption boundaryAccess boundaryAudit boundary

Storage, encryption, access, and audit are separate trust boundaries — a breach of one does not automatically collapse the others.

The full picture — what each part of ASTIS receives

Business payload — emails, documents, application fields, secrets

What ASTIS receives

Nothing — encrypted client-side, never sent to ASTIS

Where plaintext lives

Only your client endpoint / workload

Encrypted SKEY capsules

What ASTIS receives

Capsule + routing metadata

Where plaintext lives

Transiently during approved rewrap — sKey (Mail onboarding) or CVS (organization workflows)

Managed CVS key material & workload DEKs

What ASTIS receives

Sealed key material

Where plaintext lives

Transiently in CVS memory during approved operations

HYOK CVS — private key custody

What ASTIS receives

No private key material — your OpenPGP private key stays in your CVS (SKEY capsules still live in ASTIS, encrypted to your key)

Where plaintext lives

Decryption authority on your infrastructure only

WKD (Web Key Directory)

What ASTIS receives

Public keys + directory mapping

Where plaintext lives

Contains no private keys

Account & control plane

What ASTIS receives

Account, org, config, billing metadata

Where plaintext lives

Operator plane (no business payload)

Audit

What ASTIS receives

Security event metadata

Where plaintext lives

No business-payload plaintext

Hosted MCP (dev-time)

What ASTIS receives

Inputs you explicitly pass

Where plaintext lives

No runtime crypto

ASTIS never holds it transient, in memory, managed plans only operator/metadata plane

Beyond access control

Zero Trust verifies access. ASTIS limits exposure.

Zero Trust verifies who can reach a system. ASTIS controls what that system, vendor, workload, or agent can actually see. Infrastructure operators, cloud services, AI tools, and automation do their job without receiving business-payload plaintext.

One trust layer — multiple integration paths

APIs · SDKs · workload-bound secrets · workflow/YAML · MCP · HYOK key custody

Regain control over sensitive data across cloud, on-prem, and hybrid environments — products, workloads, vendors, AI tools, and operators work without becoming plaintext holders. Infrastructure can operate; sensitive data stays under your control.

COMMUNICATE

ASTIS Mail

Secure communication alongside Gmail and Microsoft 365 — no migration. Message content stays encrypted; keys and access policy are separated from mailbox storage. TTL limits long-term exposure.

BUILD WITH APIs / SDKs

ASTIS API Platform

Use APIs and SDKs to add sealed-envelope encryption, hash-only sign/verify (a 32-byte digest, never the file), FPE/tokenization, key capsules, policy checks, and tamper-evident audit to your own product — regulated-data controls without building crypto yourself.

PROTECT WORKLOADS

Workload Secrets

Adds the runtime boundary Vault/KMS does not provide. Vault/KMS governs custody and release to authorized clients; ASTIS binds plaintext release to the attested workload — decrypted only inside that workload, in RAM, at use time. Cluster admins, etcd backups, CI logs, vendors, and cluster-read agents get ciphertext.

OWN KEY CUSTODY

HYOK CVS

Keys and decryption authority stay in customer-controlled infrastructure. ASTIS coordinates cryptographic workflows without holding plaintext or key authority. HSM support; EU/EEA, US, or customer-hosted residency by agreement.

AI / MCP:

the same controls exposed to agents over MCP — sign, verify, tokenize, and request sealed operations without business plaintext in model context, unless runtime access is explicitly granted. Learn more →

Built for regulated data

NIS2 · DORA · HIPAA · GDPR · AI governance

NIS2 / DORA

Essential entities (energy, transport, health, water, digital infrastructure, public administration), financial institutions, and ICT third-party risk programs: supplier, cloud, operator, and infrastructure plaintext exposure reduced by architecture.

HIPAA / Healthcare

Providers, payers, and business associates handling PHI: HIPAA-aligned workflows with customer-controlled keys and audit evidence; BAA available for Enterprise/HYOK. No HIPAA certification claimed.

GDPR / AI governance

Art. 32 encryption support, TTL-bounded data minimisation, audit evidence, and regional deployment options including EU/EEA managed data plane and HYOK. Sensitive plaintext stays out of model context unless runtime access is explicitly granted.

Don't take trust on faith

You don't have to trust us — verify it yourself.

14/14
release builds gpg-verified Good

Verifiable signatures

Every release is signed via the same /v1/sign API and verified with gpg — no ASTIS account. You verify it yourself.

Verify it yourself
21/21
live workload checks on a real k8s cluster

Live workload checks

Workload secrets proven end-to-end, backed by 1,912 api-gateway + BFF tests green in CI.

See it work
0
plaintext bytes at the ASTIS edge

No plaintext at the edge

Business payload is encrypted on your side; the edge sees a capsule and a proof, never plaintext.

How the boundary holds
CASA T2
complete · SOC 2 Type II in progress

Honest boundary

Internal dogfood + independently verifiable artifacts — not yet a third-party audit. EU/EEA data plane.

Trust Center

Numbers are shown only where they are independently verifiable or live on a see-it-work page. Full architecture is reviewable under NDA.

Pricing

Two product lines, separately priced. Buy one, the other, or both — billed under one organization.

Packaged workspace

ASTIS Mail

From $179/ year

Solo $179/year · Team $15/seat/mo · Organization $20/seat/mo · Enterprise from $25k/year

  • End-to-end encrypted mail and calendar
  • Industry templates (legal hold, medical referral, HR severance)
  • Customer-controlled encryption keys
  • Optional Gmail and Outlook integration

Annual platform license

ASTIS API platform

Free developer access· production from $15,000/year

Pro $15k · Business $60k · Enterprise from $150k · Strategic from $1M · HYOK CVS (self-hosted) from $50k

How it works: create an evaluation organization in Portal, generate an API key, integrate. Production-grade infrastructure with rate limits and abuse-protection caps. No SLA. Production licenses are annual via sales.
  • Sealed envelope, sign / verify, FPE, audit chain
  • ASTIS-managed CVS or HYOK (self-hosted) key custody
  • Annual, feature-gated tiers sized to your workload
  • EU-hosted infrastructure

Using an AI coding agent? Connect ASTIS MCP →

Self-hosted HYOK CVS contracts are sales-led only.
See API pricing for details.

Enterprise and sovereignty contracts in the EU are with ASTIS OÜ (Estonia), activated by invoice with bank transfer or card. The contracting entity and payment method for each plan are confirmed at checkout or in your Order Form.

Frequently asked questions

Mail product, API platform, and how the two fit together.

Keep plaintext where it belongs.

Talk to ASTIS about Mail, Platform, or self-hosted custody — or verify the proof yourself first.

Self-serve: Mail free trial · free developer access — see the two paths above.