Your data, your keys, your call.
The Vault answers one question before anything else begins: who holds it? You choose your custody posture at onboarding. Every credential, every file, every data object follows from that choice.
Two postures. Equal weight. No default.
We present both options with equal emphasis. Neither is recommended over the other. Switching between them is always supported.
You hold the keys.
Your encryption keys live at your site, on your hardware. The grid receives only scoped, short-lived grants to work with your data. The moment you revoke, we hold nothing.
We hold the keys under contract.
ArcGrid holds your keys under an explicit custody contract, with per-tenant isolation, Hardware Security Module protection, and formal obligations for breach notification and audit.
Either posture, same promise: no credential is ever used outside its scope, and every use is on the record.
Every object has exactly one home.
Sovereignty generalizes from keys to all data. Every object carries a home stamp written at creation. Derived files inherit it. Mixed sources take the more protective home. Migration is gated and recorded.
The home stamp is written at object creation and checked at every access, export, and migration. It cannot be changed without a gated, recorded action.
If an agent creates a document from your data, that document inherits your data's home stamp. Sovereignty is not lost at derivative creation.
Any migration of a data object requires a named human commit. Every migration is logged. We drill restores quarterly so you know the drill works.
A staged progression, named honestly.
Sovereignty is not a checkbox. It is a progression. We name the rungs so the roadmap is legible and marketing above the delivered rung is explicitly prohibited.
Data home at your site
All data objects stamped with your site as home. Available now on both postures.
Key custody
You hold your own encryption keys. Available now in the self-custody posture.
Operational autonomy
The grid runs on your hardware with no dependency on ArcGrid's cloud for daily operations. Available on Firm and Network tracks.
Control-plane independence
Full separation from the Grid's orchestration, update, and authentication systems. On the roadmap. Not currently offered. We will not describe it as available until a tenant can choose it.