Hash-only ingestion
Your bytes are yours. We never see them.
We never see your bytes
Vitrified is hash-only by default. You compute the SHA-256 of your artifact locally — with our SDK, the CLI, or any standard tool — and submit the digest plus structured metadata via authenticated API. The bytes of the artifact never cross Vitrified’s wire. There is nothing for us to leak, subpoena, or lose.
No silent transformation
Vitrified never canonicalizes, re-encodes, or otherwise transforms your bytes on the way in. Canonicalization helpers exist in the SDK as explicit function calls you choose to invoke — the bytes you hash are the bytes you keep. If you produce them, you can re-produce them, and the witness still verifies.
Optional Vault for ciphertext custody
If you need durable custody of the artifact itself, the optional Vault upsell stores customer-encrypted ciphertext separately, with keys you manage. Plaintext bytes still never cross our wire. Vault is an add-on, not a default; the witnessing path is fully functional without it.
What this means in practice
- Sensitive source artifacts never leave the build environment.
- Regulated content stays inside your compliance perimeter.
- Sub-processor exposure is the metadata schema you chose plus the hash — nothing more.
- Wind-down or supplier change can never strand the bytes; you already hold them.
Self-serve. Subscription with volume-scaled tiers. See pricing