SECURE COLLABORATION & DATA MANAGEMENT

Your data,sealed.

Wulfos is a secure collaboration and data management platform built for government, defence and critical infrastructure. Your files are encrypted before they ever leave your device: the keys stay with your institution, and content opens only for authorised key holders. Designed to hold up against tomorrow's computers, not just today's.

LOG //contract_annex-2.pdf → sealed · opens only for authorised keys

01OUTCOMES

ERGEBNISSE

What your institution gains.

Beneath the technical detail sit three clear results.

O·01

Collaborate securely across institutional boundaries

Work with other institutions and external stakeholders without moving data over unprotected channels.

O·02

Data, infrastructure and keys stay with you

Sensitive data, the infrastructure it runs on and the cryptographic keys never leave institutional control.

O·03

Verifiable evidence of every event

Every access, change and sharing event is documented in a tamper-evident record.

02PRODUCT FAMILY

PRODUKTFAMILIE

03PLATFORM & MODULES

PLATTFORM & MODULE

One secure platform. Multiple protected workflows.

Six modules, from file sharing to e-signature, run on the same seal. Explore the capabilities, integrations and operating model on the platform page.

Explore the platform
M·01Secure files and external sharing
M·02Secure messaging and meetings
M·03Workflow and e-signature
M·04Desktop, sync and offline protection
M·05Reporting, verifiable audit and administration
M·06API and enterprise integrations

04DIFFERENTIATORS

UNTERSCHEIDUNGSMERKMALE

Four things that set Wulfos apart.

F·01

Client-side encryption with institution-controlled keys

Content is encrypted on the device; keys never leave institutional control.

F·02

On-premise, private cloud and air-gapped deployment

The infrastructure choice belongs to the institution, including fully offline networks.

F·03

Verifiable, append-only audit architecture

Every event is committed to a tamper-evident ledger; records cannot be altered afterwards.

F·04

Post-quantum key establishment

ML-KEM-768 (NIST FIPS 203), deployed within a crypto-agile architecture.

05ZERO TRUST

ZERO TRUST

Implicit trust, struck off line by line.

Traditional perimeter security works like a castle: verified once at the gate, free to move inside. That model rests on an inventory of implicit trust. The zero trust principle closes the inventory: location confers no trust, and every access is verified on its own.

We start the design from "a breach has happened", not from "a breach cannot happen". The ledger below is that decision written out: every item taken on faith in the classical architecture is struck off, and only verification remains.

TAKEN ON FAITH IN THE CLASSICAL ARCHITECTURECONCEPTUAL STATEMENT
ITEMSTATUS
01Network locationSTRUCK OFF

Coming from the internal network counts for nothing; every request is verified regardless of origin.

02The internal userSTRUCK OFF

Role-based access, multi-factor authentication and time-limited permissions: authority is granted explicitly, never assumed.

03The device and the wireSTRUCK OFF

Content is encrypted client-side before it leaves the device; signatures (Ed25519) and authenticated encryption (AES-GCM) prove origin and integrity.

04The infrastructureSTRUCK OFF

The system is designed so that the infrastructure does not need access to plaintext.

05The operatorSTRUCK OFF

Cryptographic keys do not leave organisational control.

06The recordSTRUCK OFF

History rests on the ledger, not on anyone's word: a cryptographically verifiable, append-only audit ledger surfaces every intervention.

BALANCEVERIFICATION

The default state carries no privilege. The only remaining source of trust: verify explicitly, least privilege, assume breach.

Zero trust is a principle here; the system is designed to align with it.

06SECURITY

SICHERHEIT

What if the worst happens?

We start the design from "the breach happened," not "it won't." Six scenarios, one outcome.

The full sealing process, node architecture and all six scenarios live on the Security & Trust page.

Go to the Trust Centre
WHAT THE ATTACKER GETS6 SCENARIOS · ONE OUTCOME
RESULT: CIPHERTEXT

07DEPLOYMENT

BEREITSTELLUNG

Your infrastructure, your rules.

Deployment models, commissioning and day-2 operations have a dedicated page.

Go to the Deployment page
ON-PREM · AIR-GAP
On-premises
S3 · AZURE · GCS
Hybrid cloud
MULTI-REGION · REDUNDANT
Multi-region

08AI

KI

The language model runs inside the sealed perimeter.

AI stops being safe the moment it carries your data outside the institution. So the model is positioned to run on the institution’s own infrastructure: content goes neither to a model provider nor to us.

OCR and content understanding

Uploaded documents are turned into text with OCR, then a language model processes that text for search and classification. Indexing runs on your own installation.

Full-text search across scanned documents and images · Document type and content labels · Page-level results inside encrypted storage

TXT
contract_annex-2.pdf31 pages · scanned
TXT
  • CONTRACT
  • ANNEX-2
  • SIGNED
  • TR / EN

search: "delivery period"

2 results · p.14 · p.31 · in encrypted storage

Offline assistant

The assistant we are building connects a language model running on your own servers to Wulfos; you handle file work by asking for it. The assistant acts with the user’s own permissions: a file you cannot see, it cannot see either.

Runs in an air-gapped installation · Data never leaves the institution’s server · Limited to the user’s own permissions · Every assistant action lands in the audit record

wulfos-assistant · local model · institution server
  • Send Q3-budget.xlsx to Hans Weber
  • File found
  • Recipient verified
  • Delivered
  • Written to the file log
  • I have sent Q3-budget.xlsx to Hans Weber.

09INDUSTRIES

BRANCHEN

For industries with no margin for error.

Requirements differ; the architecture is the same: only the key holder reads the content.

S·01

Government

Data never leaves the institution's boundary; on-prem install, full separation of duties.

S·02

Defence

Air-gapped deployment; a complete audit trail in the ledger.

S·03

Critical Infrastructure

Multi-region, redundant operation for energy and grid workloads; service continues through the loss of a region.

S·04

Finance

Audit-ready reporting; every action in a tamper-evident record.

S·05

Legal & Healthcare

Keys always stay in the institution; the confidentiality obligation is met by architecture.

S·06

MSSP

Managed security providers offer sealed data infrastructure to their clients as a service.

10FAQ

HÄUFIGE FRAGEN

Open questions, straight answers.

If your question isn't answered here: info@wulfos.com

Can Wulfos or system administrators access customer content?

The platform is designed so that our infrastructure does not require access to plaintext customer content. Files are encrypted before they leave your device and the keys stay under your institution's control; only encrypted data reaches our servers.

Who holds the keys?

Your institution. The Wulfos Key stays with the user, and content keys never leave institutional control; no content key is held on the server side.

What if quantum computers break the encryption?

Key establishment in the device and server layers uses ML-KEM-768 (FIPS 203), NIST's post-quantum standard. It is a safeguard designed against "harvest now, decrypt later" attacks.

Does the audit ledger have anything to do with cryptocurrency?

No. The ledger is an append-only record holding permissions and audit history that exposes any tampering. It involves no cryptocurrency or tokens and runs on CEIC-BFT consensus.

Does it work in an air-gapped (offline) environment?

Yes. The platform runs with air-gapped on-premises deployment. Wulfos Crypter is designed for fully offline encryption.

Does it integrate with our existing systems?

AD/LDAP, SIEM, SOAR, DLP, ClamAV, sandbox, Office 365, Collabora and Jitsi integrations are ready; extend via REST API.

What is the limit of the protection?

If the user's own device is compromised, end-to-end confidentiality cannot be preserved for that user. In every other scenario, all the attacker gets is ciphertext.

11 / CONTACT

Seal your data.

Evaluate the architecture against your own scenarios. Write to us from your institutional e-mail and we will answer questions with architecture.