Skip to main content
Zero Trust for data, not just access

Your data stays yours.
Sealed against breach and insider access.

Zero Trust verifies who gets in. We seal what they would find. Business software built on one rule: the people who run the servers can never read what is on them. Not hackers. Not administrators. Not even us.

Client-side encryption
Customer-held keys
No master key
No back door
Tamper-evident audit
Privately hostable
Cryptographic Zero Trust

Zero Trust has a third level. Most software stops at the second.

Never trust, always verify. The industry applied that rule to the network, then to every single request. Both still leave the server holding the keys — so both still hand a successful attacker readable data. There is one more step.

Level 1

Perimeter

Trust the network. Anything inside the firewall is treated as friendly — so one foothold inside becomes access to everything.

BREACH = FULL READ
Level 2

Zero Trust Access

Verify every request — identity, device, least privilege. A real improvement, and still not enough: the server holds the keys, so whatever passes the check reads everything.

BREACH = FULL READ
Level 3

Cryptographic Zero Trust

The server holds no keys at all. Verification can be bypassed and the answer does not change: what the attacker reaches is ciphertext. Zero Trust that survives its own failure.

BREACH = CIPHERTEXT

Levels 1 and 2 are about who gets in. Level 3 is about what is there when they do. Zeromatics is built at Level 3 — this is the standard we think business software should be held to.

Read the three levels →
The claim

Steal our servers, and you have stolen nothing.

01 · breach

A stolen database is ciphertext

There is no master key on any server. Nothing to unlock, nothing to ransom, nothing to sell.

02 · leak

Nothing readable can spill

Nothing readable exists on the server. Not in a misconfigured bucket, a dump, or a careless export.

03 · insiders

No job title opens a record

No administrator, no DBA, no vendor, not even Zeromatics. Access comes from keys you control.

Two databases are stolen. Only one makes the news.

The day of the breach
Conventional databaseDUMP IS READABLE
row_0091Ahmed K. · salary 145,000
row_0093Patient 7731 · diagnosis F32.1
row_0094Settlement offer — £40,000
ZeromaticsDUMP IS CIPHERTEXT
obj_4471a71e d40b 9f2c e338 71c4
obj_44731ad6 e905 3c4f b27a d4e1
obj_4474c58e 72f0 9b14 e6a3 0d7c
Same breach. Same attacker. Same dump. Different day entirely. And there is no key to steal.
How it works

It locks before it leaves.

01You enter it. Readable on your screen — and nowhere else.£40,000
02It locks. Encrypted on your device. The key is derived from your password and never travels.a71e·d40b
03Only the lock travels. What the data server stores is already sealed.sealed

Even we can't open it.

Why it matters

The headlines that shouldn't exist.

April 2026. Two countries, one month, one failure: the data sat readable on a server.

LAND · COURTS · TRANSPORT April 2026 · UAE

Dubai's land registry, courts and transport authority breached in one campaign

A hostile group claimed an attack on the Dubai Land Department, Dubai Courts and the Roads and Transport Authority — around 149 terabytes reportedly exfiltrated, with claims of petabytes more destroyed. Property records, case files and citizen movement data: the administrative backbone of a city, taken from its servers.

With Zeromatics: 149 terabytes of exfiltrated ciphertext is 149 terabytes of nothing.
Read the coverage ↗
NATIONAL IDENTITY April 2026 · France

19 million citizens' ID records offered for sale

France's agency for passports, national IDs and driving licences confirmed a breach. Names, dates of birth, addresses and account data of up to a third of the population — up for sale on criminal forums within a day. The flaw behind it was so basic the attacker called it 'really stupid'.

With Zeromatics: the same flaw would have served the attacker 19 million sealed records — and no keys.
Read the coverage ↗
Under the hood

Boring, audited cryptography.

No invented ciphers. The same primitives that protect Signal — applied to business software.

X25519
Key exchange
XChaCha20-Poly1305
Authenticated encryption
Ed25519
Digital signatures
Argon2id
Password key derivation
HMAC-SHA512/256
Searchable encryption
ML-KEM / ML-DSA
Post-quantum ready

See it sealed, live.

Watch your own data turn to ciphertext before it leaves the browser. The demo takes two minutes.