A record arrives
Your source system sends NDJSON batches over mutual TLS. Nothing is published before the batch digest verifies.
Customer records, transaction history, application logs, device data: Reindeer seals every JSON record with its own key, keeps the data on a closed IPFS network in Türkiye and holds the keys in HSMs. When you delete a record, its keys are destroyed and you receive a signed erasure certificate.
Reindeer is not tied to a data format. Every record carries an id, an owner and a timestamp, and you say which fields those are with JSON pointers when you open an ingest session. The owner id lets you delete every record of one person or entity with a single request.
Every step from upload to destruction can be measured and audited.
Your source system sends NDJSON batches over mutual TLS. Nothing is published before the batch digest verifies.
Every record is compressed and encrypted with its own AES-256-GCM key. That key touches no other record.
Record keys are collected in a key block per chunk; the block is wrapped by the epoch key and the DR key.
Encrypted chunks are pinned on a private IPFS network of nodes that hold the swarm key. There is no path to the public network.
A deletion enters the ledger, the weekly roll removes the record from the key blocks, and the old epoch keys are destroyed inside the HSMs.
Every record and every version of it is sealed with its own key; record keys live only inside the per-chunk key blocks.
Data stays on a private network of nodes that hold the swarm key; there is no gateway and no DHT.
Deleted records drop out of reads at once; once their keys are destroyed, copies in backups cannot be opened either.
Every sensitive action waits for a second person's passkey approval; nobody approves their own request.
Key journals are hash chained and sealed with signed checkpoints; you run the verification yourself.
Epoch, recovery and signing keys are generated inside the HSMs and stay there, non-extractable.
Deleted records drop out of reads at once. Once the keys that protected them are destroyed, even the encrypted copies left in backups cannot be opened.
Batch deletions, full exports, new identities, key loss declarations and organisation activations wait for a second person's passkey approval. Neither the requester, nor whoever invited them, nor anyone in their control chain can decide.
Sign up; two operators review and activate your organisation. A cell of your own is prepared: its own API address, database, private IPFS network, HSM partition and signing key. No request, query or key is shared with another customer.
Register your organisation; once two operators activate it, your cell is prepared. Or read the docs first.