Regulatory Readiness. Data Integrity. Liability Reduction.

An in-the-dark architecture designed to satisfy modern compliance requirements while reducing your organization's privacy liability.

In-the-Dark Architecture

Your data is never visible to the server, minimizing privacy liability concerns and satisfying strict regulatory requirements.

A Server is Not a Liability

In traditional cloud storage, the server operator is responsible for protecting your data and can be held liable in privacy breaches. With ExoServe, the server only stores encrypted blobs and has no access to the keys or plaintext data.

This architecture ensures that even if the server is compromised, attackers gain no meaningful access to your data.

No Operator Access

The server's role is strictly limited to storing encrypted data. It operates completely blind, having zero knowledge of:

  • File contents
  • File names
  • Directory structures
  • User identities

Data Sovereignty

Keep your sensitive data on-premise and under your organization's total control.

On-Premise Storage

Store your encrypted files on your own hardware, giving you complete control over your data's physical location and access.

Complete Control

Maintain full ownership of your encryption keys and data access policies. No third-party involvement in your data handling.

Geographic Compliance

Meet strict jurisdictional requirements by keeping data within specific geographic boundaries, crucial for international regulations.

Audit-Ready Architecture

Merkle tree structure ensures data integrity and provides clear audit trails.

Merkle Tree Integrity

ExoServe uses Merkle trees to create a secure, tamper-evident structure for your data. Each file and folder is cryptographically linked to its parent, creating an immutable audit trail.

Any unauthorized modification to your data will be immediately detectable through cryptographic verification, ensuring seamless compliance with strict audit requirements.

Cryptographic Standards

ExoServe strictly adheres to FIPS 140-3 standards. All cryptographic operations utilize AES-256 in GCM mode for data encryption and SHA-256 for Merkle hashing. Crucially, cryptographic material is generated and stored solely within segregated, secure browser storage, ensuring the server never holds sensitive cryptographic material.

Structure: Merkle Tree
AES-256-GCM SHA-256

Cryptographic Structure

a8f5f167...[root]
b9e6a278...[Client Document]
c1d2e3f4...[Progress Report]

Regulatory Framework Alignment

ExoServe's architecture satisfies key technical requirements. ¹

FIPS 140-3 Ready

  • AES-256-GCM encryption standard strictly enforced
  • Cryptographic keys generated and stored solely in client browser
  • SHA-256 hashing for integrity verification

Note: FIPS 140-3 validation requires OS-level software; browser implementations follow NIST guidance for cryptographic use.

HIPAA-Aligned Architecture

  • Satisfies HIPAA encryption standards (45 CFR §164.312(a)(2)(iv)), potentially exempting data from breach notification
  • In-the-dark architecture minimizes server-side liability for encrypted data
  • Organizations must implement BAAs and physical/administrative safeguards separately

GDPR-Friendly Design

  • Obfuscated file topology supports "privacy by design" (GDPR Art. 25)
  • Key-based deletion enables "right to erasure" (Art. 17)
  • Data encryption reduces risk of personal data identification

SOC 2 Security Alignment

  • Technical controls satisfy SOC 2 Security criteria (encryption, access controls)
  • Merkle tree provides verifiable data integrity logs
  • On-premise deployment models align with infrastructure controls

Compliance Disclaimer

¹ ExoServe is a technical solution that supports compliance objectives. Final regulatory compliance (HIPAA, GDPR, SOC 2, FIPS) depends on the implementing organization's policies, processes, deployment environment, and legal interpretation. ExoServe does not issue Business Associate Agreements (BAAs), certifications, or audits. Organizations must consult their legal, privacy, and security teams to establish full compliance requirements.