managed vs DIY
What the managed layer adds.
The SDK is open source (Apache 2.0), so you can run it all yourself. The managed service is for teams who would rather not build and maintain the pieces below themselves: key custody, audit evidence, alerting, and the day-to-day upkeep that comes with them.
BYOK (AWS KMS, live)
With BYOK enabled, supported stored vault records receive an extra encryption layer protected by your AWS KMS key. A DB-only compromise of deny.sh yields no plaintext and no unwrapped ciphertext without your KMS access. We STS-AssumeRole into your account on every wrap and unwrap, so your CloudTrail logs every call we make under our IAM role and a deterministic STS session name (deny-sh-byok-<tenant>). Revocation blocks future unwrapping; it cannot erase data already obtained. Available now on agents-infra and enterprise. Azure Key Vault, GCP KMS and direct hardware security module (HSM) support are planned; release dates are not announced. Setup: /byok-walkthrough. Reference: /docs#byok.
Decoy generation and Honey Mode
For supported structured types, Honey Mode returns a deterministic, type-correct fake for an incorrect password/control combination. This is separate from generating the deliberate decoya believable fake secret or message plaintext; neither layer guarantees that an attacker cannot distinguish a fake using external evidence. The decoy engine combines an LLM generator with a deterministic validator suite (Luhn, mod-97, BIP39 checksum, JWT structural, PEM tag, more), tuned against attack patterns as they emerge across the tenant base. Per-tier durable daily quotas (survive restarts), proactive 80/95/100% email alerts before the cap, and an in-app usage dashboard. Review generated samples against your own credential formats before deployment.
Threat intel across tenants
Attacks against the realism engine and validator-fail signatures get triaged centrally and shipped as validator/signature updates every tenant receives. Customers can use the shared updates in their own review process. Self-hosters get every signature once we ship it.
Reviewable activity evidence
Per-tenant append-only audit log, hash-chained (each entry binds the previous, so any tampered record breaks the chain), third-party timestamped via RFC 3161 trusted timestamp authorities with nonce-verified responses. Signed PDF receipts and an open-source command-line verifier support offline review of recorded activity. They do not prove that all access was observed or guarantee regulatory acceptance. Enterprise and Agents Infrastructure tenants can self-serve a one-click compliance evidence pack from the dashboard: a zip of audit chain, TSA tokens, signed receipts, BYOK custody and a SOC 2 / ISO 27001 control mapping, branded for your auditor. Confirm the pack’s scope with your reviewer.
Length-privacy bucketing
Pad every ciphertext to a fixed size band (padToBucket) so a dumped store reveals only a coarse size class, never the true length of each secret. This reduces length detail; the stored size band remains visible.
Avoid revealing which answer opened
The public decrypt API does not expose the real-vs-decoy branch. Your integration must also avoid revealing internal branch metadata or other distinguishing signals. For web and core SDK encryption, both passwords work together and the control filethe file that selects which message opens selects the plaintext.
Offline receipt verifier
An open-source CLI re-proves any audit-chain receipt with no call back to us: hash chain plus RFC 3161 timestamp, verified locally on the regulator's own machine. Hand them the proof, not a promise.
Compliance documents
Cyber Essentials certified today. UK GDPR and DPA live, with a published DPA. SOC 2 trust services criteria and ISO 27001:2022 Annex A mapped and operating; the formal SOC 2 Type II examination and ISO 27001 certification are planned. Firm, scope and dates will be announced once engaged. HIPAA, PCI DSS, and FedRAMP are out of scope today. Full posture and procurement-pack contents on /compliance.
Pre-built integrations
Shipped today: SAML SSO (Okta-compatible, JIT provisioning), AWS Secrets Manager as a customer-side custodian for critical encrypted material (we fetch via IAM AssumeRole, never store the value), and signed outbound webhooks for Datadog, PagerDuty, and Slack. OIDC, additional secrets-manager custodians (HashiCorp Vault, Azure Key Vault, GCP Secret Manager), additional log sinks (Splunk, CloudWatch, OpenTelemetry), and Microsoft Teams are on the roadmap. Each integration costs us once and benefits every customer. Self-hosters can use shipped integrations and maintain their own deployment.