Your data. Your perimeter. Our encryption.
Cipher never holds a readable byte of your application; the question that remains is where the ciphertext rests. There are three answers, and the strictest one keeps LockFlare out of custody entirely: encrypted builds, environment variables, version history and project metadata on storage you run, inside your network, in the jurisdiction you choose — still encrypted at the application layer before they get there.
Where the ciphertext rests
One runtime, one encryption model, one set of features. What changes between the three is only the place the encrypted build is stored — never how strongly it is protected.
On your engines only
Once a server confirms it holds a verified copy of a build, the central copy is dropped. The AES-256-GCM artifact then lives on your own machine and nowhere else; LockFlare keeps no copy at all. The cost is practical: a build is promoted by pushing it again, and a lost server is rebuilt by pushing again from the machine that still has the source.
In Cipher repositories
The encrypted artifact is also retained centrally and versioned. A build is promoted between environments by repointing — no bytes move — and a lost server pulls its artifacts and resumes. The control plane stores what it received, as it received it, and has no key to open it.
In storage you run
You provide the storage — a database inside your perimeter, on the network path you define — and the control plane and your engines read and write there instead. Everything is still encrypted before it is written. The data is yours; the keys and the tools are ours; nothing readable exists in between.
Your database, our encryption
With self-hosted storage you grant the platform a connection to a MongoDB instance you operate, with read and write access. Cipher and the engines on your servers connect to it instead of ours. All code is still AES-256 encrypted before it is written: what sits in your database is ciphertext that cannot be read without LockFlare's keys and a licensed engine. Even your own database administrators cannot read the source — accessing the raw documents reveals encrypted blobs, with no file names, no structure, no logic.
- Physical location. Any datacenter, any region, any jurisdiction — data residency for GDPR, HIPAA, FedRAMP or a national regulation.
- Backup and replication. Your own backup policies, replication strategies and disaster recovery, applied to the encrypted data.
- Network isolation. Inside your VPN, behind your firewall, on an air-gapped segment. The platform connects over the path you define.
- Audit. Every read and write is visible in your database's own logs, with your existing tooling.
When you need this
Defense and classified work
Applications whose source cannot leave sovereign infrastructure. Air-gapped segments with no external network. FedRAMP, ITAR and national-security requirements.
Healthcare
HIPAA-regulated applications whose logic must reside on compliant infrastructure; hospital systems that need on-premises storage with an auditable access trail.
Financial services
Trading platforms, banking systems and fintech subject to SOC 2, PCI DSS or regional rules that keep data within specific jurisdictions.
SaaS delivered on-premises
You sell software to enterprises that demand on-prem. The client hosts the encrypted database on their own servers, and your source is compiled and executed entirely in memory — never readable from disk, storage, backups or the wire. Close the deals you used to walk away from.
Data residency
EU organisations under GDPR localisation, or any jurisdiction where source code is classified as regulated data that must remain within national borders.
And the paperwork
LockFlare Corp is ISO/IEC 27001:2022 certified. ISMS documentation, including the Scope Statement and the Statement of Applicability, is available under NDA.
Trust and complianceThe bottom line
Self-hosted storage gives you complete control over where your encrypted data lives, while LockFlare keeps complete control over how it is accessed, decrypted and executed. The data is yours. The tools are ours. No readable source code exists on the server, in the database, in a backup, or on the wire.
Discuss your requirements
Self-hosted storage is arranged per deployment, and it is the configuration we recommend for regulated workloads. Tell us the regulation, the jurisdiction and the network, and we will tell you how it is laid out.