Security architecture

Distributed cryptographic protection. No single point of decryption authority.

VESTA separates storage, identity, policy, simultaneous control, protected cryptographic contribution and runtime execution into distinct trust boundaries.

VESTA distributed security architecture with encrypted capsules, policy, simultaneous approval, local HSM, cloud HSM and controlled decryption

Seven independent layers

Every layer has a narrow role. None is sufficient alone.

The separation prevents convenience, administrative power or infrastructure compromise from silently collapsing into full decryption authority.

01

Encrypted data layer

Objects and exam capsules remain encrypted across workstation, NAS, cloud and archive storage.

02

Minimal opaque ledger

The active database retains only the references required for lifecycle, revision and storage resolution.

03

Context and policy engine

Binds every request to identity, device, session, application, exact scope, time and risk signals.

04

Simultaneous CRP control

Required MFA contributors validate the same challenge context within the same authorization event.

05

Dual HSM contribution

A physical local HSM and an independent cloud HSM each perform a non-exportable operation.

06

Controlled execution

Runtime material exists only in memory and only for the approved data operation.

07

Signed audit evidence

Policy evaluation, approvals, cryptographic execution, content access and termination are recorded.

HSM boundary

Protected secrets never leave their HSMs.

The HSMs receive a canonical context and return opaque contributions. VESTA does not export their protected secrets or store a fully assembled runtime key.

L

Physical local HSM

  • Anchors the site-side cryptographic boundary.
  • Protects its contribution in hardware.
  • Operates only against an authorized canonical context.
  • Cannot decrypt production data independently.
C

Independent cloud HSM

  • Lives in a separate operational and administrative domain.
  • Protects its contribution in managed hardware.
  • Validates the same context and protocol version.
  • Cannot decrypt production data independently.
2 HSM domainsIndependent local and cloud contributions.
1 canonical contextUser, device, session, application and scope.
0 exported secretsProtected HSM material stays inside hardware.
Memory-only runtimeAuthorization material is erased after use.

A user can be authorized. An application can be legitimate. An HSM can be available. Decryption still occurs only when the complete threshold is met.

Review the trust boundaries

Map VESTA to your application, storage, IAM and HSM architecture.

Request a review