LockFlare

Your data. Your perimeter. Our encryption.

Cipher never holds a readable byte of your application; the question that remains is where the ciphertext rests. There are three answers, and the strictest one keeps LockFlare out of custody entirely: encrypted builds, environment variables, version history and project metadata on storage you run, inside your network, in the jurisdiction you choose — still encrypted at the application layer before they get there.

# your storage — one build document, as your DBA sees it _id 7f3a9c1e… project (encrypted) version (encrypted) payload AES-256-GCM · 2,418,112 bytes · no names, no structure created 2026-10-08T18:40:11Z # readable with: a licensed engine, in RAM. nothing else.

Where the ciphertext rests

One runtime, one encryption model, one set of features. What changes between the three is only the place the encrypted build is stored — never how strongly it is protected.

On your engines only

Once a server confirms it holds a verified copy of a build, the central copy is dropped. The AES-256-GCM artifact then lives on your own machine and nowhere else; LockFlare keeps no copy at all. The cost is practical: a build is promoted by pushing it again, and a lost server is rebuilt by pushing again from the machine that still has the source.

In Cipher repositories

The encrypted artifact is also retained centrally and versioned. A build is promoted between environments by repointing — no bytes move — and a lost server pulls its artifacts and resumes. The control plane stores what it received, as it received it, and has no key to open it.

In storage you run

You provide the storage — a database inside your perimeter, on the network path you define — and the control plane and your engines read and write there instead. Everything is still encrypted before it is written. The data is yours; the keys and the tools are ours; nothing readable exists in between.

Your database, our encryption

With self-hosted storage you grant the platform a connection to a MongoDB instance you operate, with read and write access. Cipher and the engines on your servers connect to it instead of ours. All code is still AES-256 encrypted before it is written: what sits in your database is ciphertext that cannot be read without LockFlare's keys and a licensed engine. Even your own database administrators cannot read the source — accessing the raw documents reveals encrypted blobs, with no file names, no structure, no logic.

  • Physical location. Any datacenter, any region, any jurisdiction — data residency for GDPR, HIPAA, FedRAMP or a national regulation.
  • Backup and replication. Your own backup policies, replication strategies and disaster recovery, applied to the encrypted data.
  • Network isolation. Inside your VPN, behind your firewall, on an air-gapped segment. The platform connects over the path you define.
  • Audit. Every read and write is visible in your database's own logs, with your existing tooling.
# you control where the data lives any region, any jurisdiction backups · replication your policy, on ciphertext the network path vpn · firewall · air gap the audit trail your database logs # LockFlare controls the encryption keys without them, unreadable the only client the desktop app the only reader a licensed engine, in RAM # no engine license, no execution. anywhere.

When you need this

Defense and classified work

Applications whose source cannot leave sovereign infrastructure. Air-gapped segments with no external network. FedRAMP, ITAR and national-security requirements.

Healthcare

HIPAA-regulated applications whose logic must reside on compliant infrastructure; hospital systems that need on-premises storage with an auditable access trail.

Financial services

Trading platforms, banking systems and fintech subject to SOC 2, PCI DSS or regional rules that keep data within specific jurisdictions.

SaaS delivered on-premises

You sell software to enterprises that demand on-prem. The client hosts the encrypted database on their own servers, and your source is compiled and executed entirely in memory — never readable from disk, storage, backups or the wire. Close the deals you used to walk away from.

Data residency

EU organisations under GDPR localisation, or any jurisdiction where source code is classified as regulated data that must remain within national borders.

And the paperwork

LockFlare Corp is ISO/IEC 27001:2022 certified. ISMS documentation, including the Scope Statement and the Statement of Applicability, is available under NDA.

Trust and compliance

The bottom line

Self-hosted storage gives you complete control over where your encrypted data lives, while LockFlare keeps complete control over how it is accessed, decrypted and executed. The data is yours. The tools are ours. No readable source code exists on the server, in the database, in a backup, or on the wire.

Discuss your requirements

Self-hosted storage is arranged per deployment, and it is the configuration we recommend for regulated workloads. Tell us the regulation, the jurisdiction and the network, and we will tell you how it is laid out.

Contact us