Custody you can prove. Recovery that survives the incident.
Sovereign Vault is a fully managed data custody, cryptographic proof and cyber recovery service for regulated firms. Every record, every model decision and every recovery drill leaves evidence your auditor, your regulator — or a court — can verify independently. Without taking anyone's word for it. Not even ours.
London, United Kingdom
Regulatory Vault and Sovereign Archive run on enterprise object storage in the IBM Cloud London region. Your data at rest stays in the UK, under UK jurisdiction, end to end.
São Paulo, Brazil
An encrypted, offline last-resort copy on dedicated IBM Diamondback tape infrastructure — physically and jurisdictionally separated from any event that could compromise your UK estate.
Provability
Cryptographic evidence for every object and decision — hashed at origin, chained, timestamped, publicly anchored. Cuts audit preparation from weeks of reconstruction to an export.
Sovereignty
You hold the keys. Primary data never leaves the UK; cross-border copies are encrypted before they travel. Erasure is enforced cryptographically, not contractually.
Cyber-resilience
When ransomware reaches your backups, an encrypted, air-gapped copy on another continent is the difference between an incident report and an obituary.
Your regulator no longer asks for security. It asks for proof.
Operational resilience in the UK has moved from policy statements to enforcement posture. The question is no longer whether you have controls — it is whether you can evidence them, before, during and after the incident. Most architectures cannot preserve that evidence when the supply chain itself is compromised. Sovereign Vault is built so that it can.
Operational resilience
FCA PS21/3 and PRA SS1/21: map important business services, set impact tolerances and prove you can stay within them. Sovereign Vault gives that proof a permanent home — recovery drills and restores become sealed ledger events.
Incident & third-party reporting
FCA PS26/2 and PRA PS7/26 make incident reports and a material third-party register mandatory. Every custody event is already a ledger entry: your register and your incident timeline practically write themselves.
Critical third parties
Supervision has widened from your firm to your entire supply chain. When your regulator asks what your providers can prove, heimr is the provider whose answer is an exportable evidence pack, not a slide deck.
“We do not sell cheap storage. We sell the ability to survive a regulatory inspection without panic.”
Proof that does not depend on trusting heimr.
Four steps separate your data from any dispute about it. Each one is independently verifiable — the last on a public blockchain that no one, not even heimr, can rewrite.
Hashed at origin
Dual SHA-256/512 hash computed in your environment, before the data ever reaches us.
Append-only ledger
Hash-chained evidence ledger with Merkle trees — nothing is silently altered or deleted.
Qualified timestamps
RFC 3161 timestamps from qualified time-stamping authorities.
Public anchoring
Periodic anchoring to an external public blockchain — verification without trusting heimr.
Regulatory Vault
Immutable custody for records under regulatory retention. Object-lock, WORM semantics, exportable evidence packs.
Sovereign Archive
Long-horizon archive for contracts, models, datasets and decision records — including the MRM Decision Record.
Cyber Recovery Vault
Encrypted last-resort copies on dedicated IBM Diamondback tape, offline by default, dual-control operation.
Managed custody
Ingestion, verification, retention policy and air-gap operations run by heimr — no hardware, no capital investment, no specialist headcount.
Evidence portal
Custody chain timeline and one-click evidence packs, exportable in formats your auditor and regulator already accept.
Ingestion SDK
Drops into your pipelines — including an MLflow connector that captures which model made which decision, with which data.
Open verifier
A public, open-source verification tool: any third party can check the evidence without depending on heimr.
What crosses the border — and what never does
Primary custody is entirely in-country: both live vaults operate in the IBM Cloud London region. The only data that crosses a border is the cyber recovery copy — encrypted in the UK, with keys that remain under your control in the UK, before it is written to air-gapped tape in São Paulo. The evidence ledger itself carries hashes and Merkle manifests, not readable content.
UK GDPR: a standard mechanism, engineered to be strong
Transfers to Brazil operate under the IDTA or the UK Addendum to the EU SCCs, supported by a documented Transfer Risk Assessment — which we deliver as part of onboarding, ready for your DPO to review. Encryption before transfer, UK-held keys and cryptographic erasure make that assessment unusually robust. We say this precisely: Brazil is not on the UK adequacy list today — the safeguards do not depend on it being there.
FCA / PRA outsourcing: designed for the rulebook
Offshore storage is permitted — regulated, not prohibited. Contracts guarantee unrestricted audit and access rights for you and your regulators, full data portability, and a tested exit strategy, in line with FG16/5, SYSC 8 and PRA SS2/21. Due diligence questionnaires are answered with documents we already maintain — not built from scratch on your clock.
The European bridge
EU→UK adequacy is renewed to December 2031, and the EU and Brazil adopted mutual adequacy in January 2026. If you serve EEA customers, heimr operates at both ends of the world's largest free data-flow area — a position no single-jurisdiction provider can match.
If the data goes into a GPU or answers a query, it is not for the vault. If it is large, cold, must last for years and requires air-gap or regulatory proof — it is exactly the case.
Architecture session
A 30-minute working session on your retention estate, transfer risk position and recovery posture. Technical and strategic, no commitment required.
Scoped proof of value
One retention estate or one model pipeline goes under custody. You export a real evidence pack and put it in front of your auditor — the evidence sells itself or it doesn't.
Production onboarding
Ingestion SDK into your pipelines, retention policies codified, transfer documentation delivered, first air-gap cycle executed and sealed — all as a managed service.