Your data,sealed.
Wulfos is a secure collaboration and data management platform built for government, defence and critical infrastructure. Your files are encrypted before they ever leave your device: the keys stay with your institution, and content opens only for authorised key holders. Designed to hold up against tomorrow's computers, not just today's.
01OUTCOMES
ERGEBNISSEWhat your institution gains.
Beneath the technical detail sit three clear results.
Collaborate securely across institutional boundaries
Work with other institutions and external stakeholders without moving data over unprotected channels.
Data, infrastructure and keys stay with you
Sensitive data, the infrastructure it runs on and the cryptographic keys never leave institutional control.
Verifiable evidence of every event
Every access, change and sharing event is documented in a tamper-evident record.
02PRODUCT FAMILY
PRODUKTFAMILIEOne seal, four products.
From the platform to fully offline encryption: the same architecture for every scenario.

Enterprise file storage, sharing and management platform.

End-to-end encrypted messaging and video calls.

Fully offline file encryption; built for air-gapped environments.

Fast, secure access to your files from the desktop.
03PLATFORM & MODULES
PLATTFORM & MODULEOne secure platform. Multiple protected workflows.
Six modules, from file sharing to e-signature, run on the same seal. Explore the capabilities, integrations and operating model on the platform page.
Explore the platform04DIFFERENTIATORS
UNTERSCHEIDUNGSMERKMALEFour things that set Wulfos apart.
Client-side encryption with institution-controlled keys
Content is encrypted on the device; keys never leave institutional control.
On-premise, private cloud and air-gapped deployment
The infrastructure choice belongs to the institution, including fully offline networks.
Verifiable, append-only audit architecture
Every event is committed to a tamper-evident ledger; records cannot be altered afterwards.
Post-quantum key establishment
ML-KEM-768 (NIST FIPS 203), deployed within a crypto-agile architecture.
05ZERO TRUST
ZERO TRUSTImplicit trust, struck off line by line.
Traditional perimeter security works like a castle: verified once at the gate, free to move inside. That model rests on an inventory of implicit trust. The zero trust principle closes the inventory: location confers no trust, and every access is verified on its own.
We start the design from "a breach has happened", not from "a breach cannot happen". The ledger below is that decision written out: every item taken on faith in the classical architecture is struck off, and only verification remains.
Coming from the internal network counts for nothing; every request is verified regardless of origin.
Role-based access, multi-factor authentication and time-limited permissions: authority is granted explicitly, never assumed.
Content is encrypted client-side before it leaves the device; signatures (Ed25519) and authenticated encryption (AES-GCM) prove origin and integrity.
The system is designed so that the infrastructure does not need access to plaintext.
Cryptographic keys do not leave organisational control.
History rests on the ledger, not on anyone's word: a cryptographically verifiable, append-only audit ledger surfaces every intervention.
The default state carries no privilege. The only remaining source of trust: verify explicitly, least privilege, assume breach.
Zero trust is a principle here; the system is designed to align with it.
06SECURITY
SICHERHEITWhat if the worst happens?
We start the design from "the breach happened," not "it won't." Six scenarios, one outcome.
The full sealing process, node architecture and all six scenarios live on the Security & Trust page.
Go to the Trust Centre07DEPLOYMENT
BEREITSTELLUNGYour infrastructure, your rules.
Deployment models, commissioning and day-2 operations have a dedicated page.
08AI
KIThe language model runs inside the sealed perimeter.
AI stops being safe the moment it carries your data outside the institution. So the model is positioned to run on the institution’s own infrastructure: content goes neither to a model provider nor to us.
OCR and content understanding
Uploaded documents are turned into text with OCR, then a language model processes that text for search and classification. Indexing runs on your own installation.
Full-text search across scanned documents and images · Document type and content labels · Page-level results inside encrypted storage
- CONTRACT
- ANNEX-2
- SIGNED
- TR / EN
search: "delivery period"
2 results · p.14 · p.31 · in encrypted storage
Offline assistant
The assistant we are building connects a language model running on your own servers to Wulfos; you handle file work by asking for it. The assistant acts with the user’s own permissions: a file you cannot see, it cannot see either.
Runs in an air-gapped installation · Data never leaves the institution’s server · Limited to the user’s own permissions · Every assistant action lands in the audit record
- Send Q3-budget.xlsx to Hans Weber
- File found
- Recipient verified
- Delivered
- Written to the file log
- I have sent Q3-budget.xlsx to Hans Weber.
09INDUSTRIES
BRANCHENFor industries with no margin for error.
Requirements differ; the architecture is the same: only the key holder reads the content.
Government
Data never leaves the institution's boundary; on-prem install, full separation of duties.
Defence
Air-gapped deployment; a complete audit trail in the ledger.
Critical Infrastructure
Multi-region, redundant operation for energy and grid workloads; service continues through the loss of a region.
Finance
Audit-ready reporting; every action in a tamper-evident record.
Legal & Healthcare
Keys always stay in the institution; the confidentiality obligation is met by architecture.
MSSP
Managed security providers offer sealed data infrastructure to their clients as a service.
10FAQ
HÄUFIGE FRAGENOpen questions, straight answers.
If your question isn't answered here: info@wulfos.com
Can Wulfos or system administrators access customer content?
The platform is designed so that our infrastructure does not require access to plaintext customer content. Files are encrypted before they leave your device and the keys stay under your institution's control; only encrypted data reaches our servers.
Who holds the keys?
Your institution. The Wulfos Key stays with the user, and content keys never leave institutional control; no content key is held on the server side.
What if quantum computers break the encryption?
Key establishment in the device and server layers uses ML-KEM-768 (FIPS 203), NIST's post-quantum standard. It is a safeguard designed against "harvest now, decrypt later" attacks.
Does the audit ledger have anything to do with cryptocurrency?
No. The ledger is an append-only record holding permissions and audit history that exposes any tampering. It involves no cryptocurrency or tokens and runs on CEIC-BFT consensus.
Does it work in an air-gapped (offline) environment?
Yes. The platform runs with air-gapped on-premises deployment. Wulfos Crypter is designed for fully offline encryption.
Does it integrate with our existing systems?
AD/LDAP, SIEM, SOAR, DLP, ClamAV, sandbox, Office 365, Collabora and Jitsi integrations are ready; extend via REST API.
What is the limit of the protection?
If the user's own device is compromised, end-to-end confidentiality cannot be preserved for that user. In every other scenario, all the attacker gets is ciphertext.
Seal your data.
Evaluate the architecture against your own scenarios. Write to us from your institutional e-mail and we will answer questions with architecture.