A license is an identity, not a bill.
In Cipher a license is a security instrument first. Each of your servers holds one, bound to its own address; the engine authenticates with it to fetch builds, and every encrypted payload is keyed to it — which is why a build for one server is not usable on another. Remove the license and the machine stops being able to decrypt anything. That is a scoping mechanism your security model depends on, and it works the same whatever the commercial terms.
What a license does
Binds a server
Registering a server in Cipher issues a key bound to that machine's public IP. The engine presents it on every boot; the control plane checks it against the account and the source address. A typo in the address produces a machine that never comes online — the binding is real.
Keys the builds
Every encrypted payload delivered to a server is keyed to that server's license. The same build, intercepted or copied to another box, is ciphertext there.
Roots the seal
The AES-256 backup that lets a sealed server be unsealed is held under a license-derived key. The license is the root of trust for Enclave, and it is in your custody.
Never reaches your app
The engine's own environment is not passed through to your application. A read of the engine's .env from your code returns nothing, so a compromised application cannot lift the credential that identifies the server.
Is visible, per server
The Licensing screen shows every server's key and what is allocated and free across the fleet — servers, cores, environments, seats — as live gauges that turn red at the ceiling, so you see you are about to run out before an action fails.
Can be taken away
Remove a server's license and the engine on it can no longer fetch or decrypt anything. The machine keeps running what is already in memory until it restarts, and then it is a blank box.
What is counted
Four axes, each independent of the others, and the terms for them agreed per deployment.
Servers
An engine instance on your infrastructure — cloud, bare metal, or air-gapped. One license each.
Cores
CPU cores the runtime may use, as a pool across the fleet: you decide the split per server, and move capacity between servers without reinstalling.
Developer seats
A named account in Cipher with its own permissions, login rules and audit trail. Removing a member frees a seat immediately.
Environments
Development, UAT, Live, one per client — each isolated, with its own servers, domains and push rules.
Why it is not a public download
Cipher makes source code unreadable on the server that runs it. That is exactly what a software vendor, a defense contractor or a bank wants from it, and exactly what we do not want in the hands of someone who intends to hide what a program does from the people whose machine it runs on. So we want to know who is running it: Cipher is licensed to companies we have spoken with, for the applications they name, and the conversation starts with what you deploy, where, and to whom.
Enterprise arrangements cover unlimited servers and cores, dedicated infrastructure, custom service levels, air-gapped and government deployments, priority support, and self-hosted storage that removes LockFlare from artifact custody entirely. Private demos, architecture reviews and compliance documentation under NDA all come through the same conversation.
Self-hosted storage and data sovereigntySerious to adopt
LockFlare Corp is ISO/IEC 27001:2022 certified, and the engineering behind Cipher won The Hacker News Awards 2026 for Runtime Security. The certifications, the audits and the security review cycle apply to everything on this page. What you have deployed keeps working on the terms you deployed it under.
Trust and complianceTell us what you deploy
Write to us with the application, where it will run and who it is for, and we will walk you through Cipher on your own servers.