:: Sovereign Vault · London

Custody you can prove. Recovery that survives the incident.

Sovereign Vault is a fully managed data custody, cryptographic proof and cyber recovery service for regulated firms. Every record, every model decision and every recovery drill leaves evidence your auditor, your regulator — or a court — can verify independently. Without taking anyone's word for it. Not even ours.

ISO/IEC 27001 certified · IBM partner · London (Level39, Canary Wharf) & São Paulo
Primary custody

London, United Kingdom

Regulatory Vault and Sovereign Archive run on enterprise object storage in the IBM Cloud London region. Your data at rest stays in the UK, under UK jurisdiction, end to end.

Air-gapped cyber recovery

São Paulo, Brazil

An encrypted, offline last-resort copy on dedicated IBM Diamondback tape infrastructure — physically and jurisdictionally separated from any event that could compromise your UK estate.

01

Provability

Cryptographic evidence for every object and decision — hashed at origin, chained, timestamped, publicly anchored. Cuts audit preparation from weeks of reconstruction to an export.

02

Sovereignty

You hold the keys. Primary data never leaves the UK; cross-border copies are encrypted before they travel. Erasure is enforced cryptographically, not contractually.

03

Cyber-resilience

When ransomware reaches your backups, an encrypted, air-gapped copy on another continent is the difference between an incident report and an obituary.

:: The UK regulatory reality

Your regulator no longer asks for security. It asks for proof.

Operational resilience in the UK has moved from policy statements to enforcement posture. The question is no longer whether you have controls — it is whether you can evidence them, before, during and after the incident. Most architectures cannot preserve that evidence when the supply chain itself is compromised. Sovereign Vault is built so that it can.

In force since Mar 2025

Operational resilience

FCA PS21/3 and PRA SS1/21: map important business services, set impact tolerances and prove you can stay within them. Sovereign Vault gives that proof a permanent home — recovery drills and restores become sealed ledger events.

Deadline: 18 Mar 2027

Incident & third-party reporting

FCA PS26/2 and PRA PS7/26 make incident reports and a material third-party register mandatory. Every custody event is already a ledger entry: your register and your incident timeline practically write themselves.

FSMA 2023

Critical third parties

Supervision has widened from your firm to your entire supply chain. When your regulator asks what your providers can prove, heimr is the provider whose answer is an exportable evidence pack, not a slide deck.

“We do not sell cheap storage. We sell the ability to survive a regulatory inspection without panic.”
:: The evidence chain

Proof that does not depend on trusting heimr.

Four steps separate your data from any dispute about it. Each one is independently verifiable — the last on a public blockchain that no one, not even heimr, can rewrite.

01

Hashed at origin

Dual SHA-256/512 hash computed in your environment, before the data ever reaches us.

02

Append-only ledger

Hash-chained evidence ledger with Merkle trees — nothing is silently altered or deleted.

03

Qualified timestamps

RFC 3161 timestamps from qualified time-stamping authorities.

04

Public anchoring

Periodic anchoring to an external public blockchain — verification without trusting heimr.

Public, open-source verifier Crypto-shredding: UK GDPR erasure without breaking the evidence chain Post-quantum ready: ML-DSA (FIPS 204) signatures, ML-KEM (FIPS 203) transport Evidence renewal (ERS/RFC 4998, PAdES-LTA) before algorithms age
:: Three vaults, one contract
London · Online

Regulatory Vault

Immutable custody for records under regulatory retention. Object-lock, WORM semantics, exportable evidence packs.

Built for: supervisory requests answered in hours, not weeks.
London · Online

Sovereign Archive

Long-horizon archive for contracts, models, datasets and decision records — including the MRM Decision Record.

Built for: proving which model made which decision, years later.
São Paulo · Air-gapped

Cyber Recovery Vault

Encrypted last-resort copies on dedicated IBM Diamondback tape, offline by default, dual-control operation.

Built for: the day everything else is compromised.
:: The service at a glance

Managed custody

Ingestion, verification, retention policy and air-gap operations run by heimr — no hardware, no capital investment, no specialist headcount.

Evidence portal

Custody chain timeline and one-click evidence packs, exportable in formats your auditor and regulator already accept.

Ingestion SDK

Drops into your pipelines — including an MLflow connector that captures which model made which decision, with which data.

Open verifier

A public, open-source verification tool: any third party can check the evidence without depending on heimr.

:: The hybrid model, stated plainly — for your CISO and your DPO

What crosses the border — and what never does

Primary custody is entirely in-country: both live vaults operate in the IBM Cloud London region. The only data that crosses a border is the cyber recovery copy — encrypted in the UK, with keys that remain under your control in the UK, before it is written to air-gapped tape in São Paulo. The evidence ledger itself carries hashes and Merkle manifests, not readable content.

UK GDPR: a standard mechanism, engineered to be strong

Transfers to Brazil operate under the IDTA or the UK Addendum to the EU SCCs, supported by a documented Transfer Risk Assessment — which we deliver as part of onboarding, ready for your DPO to review. Encryption before transfer, UK-held keys and cryptographic erasure make that assessment unusually robust. We say this precisely: Brazil is not on the UK adequacy list today — the safeguards do not depend on it being there.

FCA / PRA outsourcing: designed for the rulebook

Offshore storage is permitted — regulated, not prohibited. Contracts guarantee unrestricted audit and access rights for you and your regulators, full data portability, and a tested exit strategy, in line with FG16/5, SYSC 8 and PRA SS2/21. Due diligence questionnaires are answered with documents we already maintain — not built from scratch on your clock.

The European bridge

EU→UK adequacy is renewed to December 2031, and the EU and Brazil adopted mutual adequacy in January 2026. If you serve EEA customers, heimr operates at both ends of the world's largest free data-flow area — a position no single-jurisdiction provider can match.

:: Where it earns its keep
Regulatory audits & skilled person reviews M&A due diligence Litigation & disclosure Post-ransomware recovery AI & model accountability Long-term retention (7–25 years)

If the data goes into a GPU or answers a query, it is not for the vault. If it is large, cold, must last for years and requires air-gap or regulatory proof — it is exactly the case.

:: How an engagement starts
01

Architecture session

A 30-minute working session on your retention estate, transfer risk position and recovery posture. Technical and strategic, no commitment required.

02

Scoped proof of value

One retention estate or one model pipeline goes under custody. You export a real evidence pack and put it in front of your auditor — the evidence sells itself or it doesn't.

03

Production onboarding

Ingestion SDK into your pipelines, retention policies codified, transfer documentation delivered, first air-gap cycle executed and sealed — all as a managed service.

Talk to us
Explore our solutions

LONDON

LEVEL39, One Canada Square, Canary Wharf, 39th floor
London, E14 5AB
UNITED KINGDOM

SAO PAULO

WTC, Av. das Nações Unidas, 12551, 24o andar
Brooklin, São Paulo
BRAZIL