SERVICE 01 — SEALED DELIVERY

Certified mail for your data

Every business moves things it would not want read on the way. A signed contract going from your inbox into your case system. A payment instruction going from finance into the bank portal. A patient record going from a scanner into a chart. A job photo going from a phone in a parking lot into dispatch.

Today, almost all of that travels readable. It sits in a mailbox, in a form vendor's database, in a file-sharing link that works for anyone who has it, on a server belonging to a company you have never audited. Nothing has to be broken into for it to leak — someone only has to already be somewhere they should not be, and everything they find is legible. When it goes wrong, the second problem arrives immediately after the first: you cannot say precisely what was exposed, or prove what was not.

Sealed Delivery changes what is actually in transit. Content is locked into an envelope the instant it leaves one system and can only be opened inside the next one, by a key we do not hold and cannot produce. What travels in between is unreadable — to us, to your vendors, to whoever eventually gets into the mailbox. And every movement leaves a receipt, so the question "what moved, when, and who opened it" has an answer you can hand to somebody else.

Nothing about how your business runs has to change. We sit between the systems you already have, and we handle the part in the middle — the part where information is usually readable by anyone who happens to be holding it.

01 — YOU SEND

You send

From wherever the information already lives: an email, a form on your website, your own dashboard, a phone system, an AI assistant. You keep working exactly the way you work today.

02 — WE SEAL AND CARRY

We seal and carry

The content is locked into an envelope only the recipient's key can open, and we carry it blind. We can see that something moved, how big it was, and when. We cannot see what it said.

03 — THEY OPEN

They open

It opens inside the receiving system, where it was always meant to be read — and the delivery is written to a permanent record with the time, the recipient, and a receipt you can produce later.

WHAT YOU GET

The engagement, in four lines

  • Encrypted transport wired between the systems you already run — no migration, no new platform
  • Content sealed the moment it leaves one system and opened only inside the next
  • Delivery receipts and a verifiable record of every movement
  • Fixed-rate metered billing: you pay only for what moves, nothing for what sits still

For your engineers: click any hop to see exactly what happens on it.

HOW A PAYLOAD TRAVELS

Four systems, one sealed object, five authenticated hops

Click any edge in the map to inspect that hop: the mutual attestation exchange, the negotiated cipher suite, the envelope header with its per-hop key ID, and the audit entry the hop emits. Every hop is genuinely different, because every origin proves itself differently.

EMAIL WEB FORM PHONE SYSTEM AI AGENT OPS DASHBOARD ARCHIVE hop 1 · email ingress hop 1 · browser-sealed form hop 1 · telephony bridge hop 2 · attested agent hop 3 · escrow archive
handshake transcript

Select an edge in the map to open its hop transcript.

Each hop negotiates its own suite, proves its own identity, and derives its own key. Nothing is reused across hops — a compromised hop key opens exactly one hop.

Edges are keyboard-focusable. Tab to a hop and press Enter to inspect it.

PROVE IT TO YOURSELF

Don't take our word for it. Take your browser's.

The console below is not a mock-up. It generates two real ECDH P-256 key-pairs, derives a shared AES-256-GCM key, encrypts what you type, hashes the ciphertext with SHA-256, and decrypts it on the other side — entirely inside this tab, with no network calls. The middle column shows every field the relay would actually hold.

live seal console · webcrypto
Origin — your service
KryptAPI relay (zero-knowledge)
envelope
bytes
iv
origin
dest
time

this is everything we can see

Destination — their service
sealed
sealed → relayed → attested — run the ceremony to generate a signed line.

Nothing you type leaves this page. There is no endpoint behind this widget — that is the point of showing you the primitives instead of a video.

THE GUARANTEES SEALED INTO EVERY ENVELOPE

Four promises, sealed into the object itself

Open an envelope to read it. It stays open — a desk of read correspondence is exactly the mental model we want you to leave with.

WORKS WITH WHAT YOU RUN

No migration. Sealing is a hop, not a platform.

KryptAPI sits between the systems you already operate. Anything that can make an HTTPS call can seal, relay, and open — which in practice means everything on this row.

EmailIngress sealed at the transfer boundary; the mailbox is never trusted.
FormsSealed in the visitor's browser before submit — the edge sees ciphertext.
TelephonyTranscript and recording sealed as separate envelopes on one route.
LLM agentsModel identity attested; sealed model input and output on both legs.
WebhooksSigned, sealed delivery with idempotent replay and receipt-of-open.
DashboardsOpens envelopes in-process; plaintext never crosses your perimeter.
QueuesSealed payloads survive at-least-once delivery; replays are detected.
ArchivesEscrow-held archive keys; the relay cannot derive them, ever.
WHAT IT COSTS

You pay for what moves, and nothing for what sits still

Billing is metered against the movements themselves, at rates fixed in your agreement and printed verbatim on every statement. There are no seats to count, no platform fee, and no tier that stops fitting the month your volume changes.

We don't do surprise math.