Understand the protection. Plan your integration.

Architecture

How InvisiCloud works

Data processing and key control are separated, enabling joint computation without giving any single component access to plaintext. Authorized applications can access data as usual.

Your App

InvisiCloud

Payload Gateway

Encrypted TLS payload

Encrypted
SMPC

No plaintext
No single-party control

Key Gateway

TLS encryption keys

Your Storage

Encrypted PayloadEncryption KeysTrust boundary

Encrypted SMPC Computation

Executes application logic on encrypted data, such as seamless TLS termination and encryption at rest, without exposing plaintext within the middleware or giving any party sole control.

Select a component for details.

Built on Secure Multi-Party Computation (SMPC) and our patented TLShare.

Security & Control

Who can access what?

Protected content

Sensitive information remains cryptographically protected across storage, transfer and middleware processing.

Payload Gateway

Encrypted TLS payloads, without the corresponding TLS encryption keys.

Key Gateway

TLS encryption keys, without the corresponding payloads.

Distributed control

Data processing and key control are distributed across independent components, so neither can access plaintext on its own.

Authorized access

Authorized users and applications access plaintext through existing workflows and access controls.

Security boundaries

Metadata may remain visible. Confidentiality depends on separate control of the Payload Gateway and Key Gateway.

Integration & Deployment

Fits your existing setup

  1. Choose your deployment

    Decide who operates the Payload Gateway and Key Gateway: you, utilacy, or a trusted partner. Deploy using provided containers or choose a managed setup.

    Component operation

    Payload Gateway Key Gateway

    You · utilacy · trusted partner

    Independent control of the gateways

  2. Connect your storage

    Configure InvisiCloud to use your existing storage services just like a regular client.

    S3-compatible interface

    InvisiCloud Your Storage
  3. Connect your application

    Point your application to InvisiCloud directly or via DNS. Your existing storage workflow remains in place.

    Application connection

    Your Application InvisiCloud

    TLS handshake ↔ Key Gateway

    Encrypted TLS payload → Payload Gateway

Compare approaches

Different approaches. Different trade-offs.

Common security architectures prioritize confidentiality, compatibility, and control differently.

Advantage Trade-off Higher effort or limitation

Expand an approach to compare architecture, operating responsibilities and trust boundaries.

ApproachConfidentialityTrust & controlCompatibilitySetup complexityOperational overhead
Trade-off: Provider may access plaintext Higher effort or limitation: Trust concentrated in provider Advantage: Native integration Advantage: Low Advantage: Low
Advantage: Encrypted before upload Trade-off: Clients hold plaintext & keys Higher effort or limitation: Client changes required Higher effort or limitation: Per-application integration Higher effort or limitation: Client & key lifecycle
Trade-off: Gateway sees plaintext Higher effort or limitation: Trust concentrated in gateway Advantage: Supported apps unchanged Trade-off: Gateway integration Trade-off: Gateway & key lifecycle
Advantage: Protected inside enclave Trade-off: Hardware & attestation trust Trade-off: Workload adaptations Higher effort or limitation: Enclave integration Higher effort or limitation: Specialized platform lifecycle
Advantage: Neither gateway alone can access plaintext Advantage: Control split across independent operators Advantage: Existing applications & storage workflows unchanged Trade-off: Gateway deployment & routing Trade-off: Two gateways & key lifecycle

Ratings describe typical architectures; effort and protection depend on deployment. InvisiCloud reflects the target architecture and planned capabilities. See Technical Evaluation for current availability.

Technical Evaluation

Evaluate InvisiCloud for your environment

Validate the key requirements for your workload and infrastructure.

Understand → Evaluate → Test

Ready to evaluate your workload?

Verify your required interfaces, setup, security requirements and performance targets.

Technical FAQ

Your technical questions, answered.

Have a question about your workload? Contact us