CircleKey Cloud
The backend you’d have built, without building it.
It stores encrypted records, keeps each vault’s membership history in strict order, and gets out of the way. That is the entire job — small enough to describe completely on one screen, and deliberately the entire product. Hosted in the EU or the US, your choice.
What it actually does
Four responsibilities. Everything else — encryption, key management, membership authorisation — happens on your users’ devices, where we cannot reach it.
Stores encrypted records
Ciphertext in, ciphertext out, byte for byte. We never parse, transform or inspect it, because there is nothing in it we could read.
Keeps vault history in order
Membership changes are append-only and strictly sequential. We guarantee that two conflicting changes can never both be accepted — the one concurrency guarantee the protocol asks a backend for. We order them by their version number, which is all we can read: the change itself is sealed.
Rejects stale writes
A write tagged with an out-of-date vault version is refused. This is why a removed member’s queued write cannot land after their removal.
Serves history to clients that ask
Clients poll for changes and catch up automatically on reconnect, so a device that was closed, offline or on a plane resyncs without anything special from you. Live server push is something the protocol permits and we do not currently offer.
Straight answers
What we can and cannot see.
You are about to trust a vendor with your users’ data. You should know precisely what that vendor holds — which, since we are a third party rather than your own server, we deliberately made as little as we could.
◐ Visible to us, in plaintext
- The vault’s identifier and its version counter
- Its size class — an upper bound like “up to 15 members”, not the membership
- That a change happened, and when — never what kind
- Derived record identifiers, their size bucket, and how many there are
- The salt and parameters on a recovery backup, under a blinded handle
● Never received by us at all
- Any plaintext your users write, of any kind
- Who is in the vault — identifiers, device keys, manager flags
- What any change did, or whether anyone was removed
- The vault’s governance policy, or who signed anything
- Any vault key, per-record key, device private key or recovery credential
- The contents of any sealed envelope, change body or backup blob
- Anything that would let us decrypt, forge or join
And the ordinary operational truth: beyond the fields above we hold what any hosted service holds — your billing account, and the IP addresses, user agents and timings in our request logs, which we keep for 30 days. That is real metadata and no amount of padding removes it. We are also a single point of availability: a service that is down or throttled cannot serve your users. We cannot read or forge anything, because clients verify everything themselves — but downtime is a genuine thing we can do to you. That is exactly why the export and the build-your-own route below are not decoration.
Pricing
Priced per vault, because that is what you sell.
A vault is a matter, a patient’s care team, a deal room, an investigation — the unit your own business bills for. So we charge for those, and for nothing else that would punish you for using the product properly. There is no per-seat charge, no per-device charge, and no way for us to add one: our own authentication makes your users indistinguishable to us. Every plan includes a 14-day free trial.
CircleKey Cloud is not open for signup yet. The plans below are what we intend to launch with, not an offer — the prices and limits may change before they go live. If you are evaluating CircleKey seriously, the library works today against your own backend, and a short email gets you told when the hosted service opens.
| Developer $29 /mo | Team $149 /mo | Business $449 /mo | Enterprise from $1,500 /mo | |
|---|---|---|---|---|
| Best for | Building it, and evaluating properly | A product in production | Scale, or a compliance conversation | Regulated, contractual, or self-hosted |
| Included vaults | 25 | 250 | 1,000 | Negotiated |
| Additional vaults | $1.20 each | $0.80 each | $0.50 each | Negotiated |
| Fair use | 1 GB stored and 2 GB transferred per vault, pooled across your account | |||
| Byte overage | $0.05 per GB stored · $0.05 per GB transferred — the same on every plan, no penalty rate | |||
| Users & devices | Never counted, on any plan — we cannot tell your users apart, by design | |||
| Re-keying | Unlimited, on any plan — we do not charge for rotating keys | |||
| Sync | Clients poll and catch up automatically on reconnect — same on every plan | |||
| Region | EU or US | EU or US | Pinned | Pinned or dedicated |
| Uptime target | — | 99.9% | 99.9% | 99.95% |
| Ciphertext export | Self-serve | Self-serve | Self-serve | Assisted |
| Support | AI first line, escalating to a human | Human reply, one business day | Priority, plus DPA and subprocessor list | Named contact, SLA, questionnaire support |
| Notify me | Notify me | Notify me | Talk to us | |
Somewhere between two tiers, or need the data somewhere specific? Mail us and we will quote against your actual numbers rather than a tier you have to grow into.
What we deliberately don’t charge for.
Metering shapes behaviour. These three are metered by plenty of vendors, and every one of those meters pushes a customer towards the less safe choice.
Re-keying is free and unlimited
Every membership change mints a new vault key. Charging per change would put a price on the single mechanism that makes the product secure. We are not going to invoice you for good hygiene.
Users and devices are not counted
There is no per-seat charge and no per-device charge, and this one is not generosity: requests are authenticated so that we learn a member of this vault made them, never which member. We could not bill per user if we wanted to. So we meter the three things we can honestly see — vaults, stored bytes, and egress.
There is no “encryption tier”
Every plan gets identical cryptography, because encryption happens on your users’ devices and we could not sell it back to you if we wanted to. Money buys capacity, region choice, and a contract — never security.
The other door
Build your own backend instead.
CircleKey is a front-end library that talks to storage through one interface. We publish that interface and we do not hold a privileged position behind it. If you would rather run it yourself — or need to, for procurement reasons — here is the whole job.
A short list of operations
Create a vault, read its current state, submit and fetch membership changes, optionally subscribe to them, put and get and list records, and store one recovery blob per user. Any wire format you like — REST, GraphQL, WebSocket, whatever your stack already speaks.
A handful of rules
Keep membership history append-only and strictly unique per version. Reject writes tagged with a stale version. Store the opaque fields byte-for-byte, without parsing them and without trimming their padding. Verify the signature on each request — any published vault key for reads, the current one for writes. That is the complete set of guarantees the client depends on.
An executable acceptance test
runHostIntegrationScenario from circlekey/testing drives
your implementation through the whole client-observable contract and names the exact
assertion that failed. You are not guessing whether you got it right.
Export is a ciphertext dump
Records, membership history and recovery blobs are bytes we cannot interpret anyway. Move them to another host and clients re-verify the whole chain from scratch against the new one — the history does not know or care who served it.
We would rather win the customers who stay because operating this is boring than the ones who stay because leaving is hard. The backend interface, in detail →
Questions we get asked
- Can you read our data?
- No. We never receive plaintext, vault keys or private keys — they are not part of any request the client makes. Nor do we receive the member list, the roles, the policy, or what any change did. We can see everything in the left-hand column above, plus the IP and timing of every request, so read that rather than take our word for the headline.
- Could you add yourselves to a vault?
- No. Adding a member requires a signature from a device that already held the authority to do it, and we hold no such key. Every client checks that signature and the chain it sits in before accepting anything, so a forged change is rejected everywhere at once.
- Can you tell who is in one of our vaults?
- No. The membership list, the manager flags and the governance policy are encrypted to the vault’s own members, and the key envelopes we store carry no recipient addresses — there is a fixed number of them per vault, most of which are decoys indistinguishable from the real ones. We cannot count your members, name them, or tell a join from a removal. What we can see is that a vault changed, and when.
- Could you lock us out?
- Yes — availability is the one thing a hosted service genuinely controls. We can’t read or forge, but we can fail. That is why every plan can export its ciphertext at any time and why the backend interface is public.
- Has this been independently audited?
- Not yet. No third party has reviewed the library or this service. When one has, we will publish the report in full, findings included.
- Do we have to use CircleKey Cloud to use CircleKey?
- No. The library is MPL-2.0 and works against any backend that implements the interface, including one you write. We sell convenience, not a lock.
- What happens the moment we remove a member?
- The vault re-keys and they receive no copy of the new key, so everything written afterwards is unreadable to them. What they had already downloaded stays on their device — no protocol can reach into a machine you don’t control and delete it, and we would distrust anyone who claimed otherwise.
- Where is the data stored?
- In the region you pick — EU or US on Developer and Team, a pinned region on Business and above — and encrypted at rest by the hosting provider on top of the encryption your users’ devices already applied. The provider itself is named in our subprocessor list rather than here, because we deliberately built the storage layer to be portable between them: an infrastructure vendor should be something we can change without changing what you depend on.
Start with the trial. Keep the exit.
Fourteen days, no commitment, and an export button that works from day one. Tell us roughly what you are building and we will get you a key.