Custody you can prove. Recovery that survives the incident.
Sovereign Vault holds what your firm must retain and delivers the evidence ready, in forms your auditor, regulator and a court already accept. Four tiers of service. Start with what you need and scale without changing supplier, contract or architecture.
Start with what you need today. Scale without a migration project.
The architecture is identical across all four tiers. What changes is how far the proof reaches, and how much trust in heimr it still requires. Moving up a tier is a commercial decision, not a platform change.
Deep Archive
Your cold estate on tape, physically off the network, with a monthly receipt that evidences integrity object by object.
Delivery over S3 or SFTP across a dedicated private circuit. Hashed on arrival. Written to an IBM Diamondback tape library in a physically segregated facility, catalogued by media, position and manifest.
Custody
Answer a supervisory request inside the deadline, with the date attested by an accredited third party.
Adds the Regulatory Vault and Sovereign Archive in the cloud: object lock in compliance mode, per-object retention and legal hold, RFC 3161 timestamps on manifests, plus a portal with searchable catalogue and access trail.
Assurance
The proof still stands even if heimr itself is compromised.
Adds an append-only evidence ledger with Merkle trees, daily anchoring of the root to an external public record, PAdES/CAdES evidence packs, and the Cyber Recovery Vault on air-gap separate from the cloud plane, with clean-room recovery exercises and a signed report.
Sovereign+
Any expert verifies your evidence unaided, without asking heimr for anything.
Adds the public open-source verifier, customer-held keys in a dedicated HSM, hybrid post-quantum signatures alongside the classical chain, and scheduled evidence renewal before algorithms age out.
Deep Archive starts with a single estate. Higher tiers are sized by volume and retention profile.
At Deep Archive the custody copy sits on tape in São Paulo: another continent, offline, out of reach of anything that compromises your UK estate. IDTA or UK Addendum plus a Transfer Risk Assessment come with onboarding, not as a billed project. If your policy requires primary custody in the UK, start at Custody instead.
In 30 minutes, find out which tier you are on.
A working conversation about your estate: what must be retained, for how long, under which rules, and what you could not evidence today if asked.
Book a conversationLondon, United Kingdom
Regulatory Vault and Sovereign Archive on enterprise object storage in the IBM Cloud London region. Primary copies remain in the UK, under UK jurisdiction.
São Paulo, Brazil
Encrypted offline copy on a dedicated IBM Diamondback tape library in a physically segregated facility, dual control, every open and close recorded as a custody event. This is recovery capacity, not a claim of UK data sovereignty in Brazil.
No public internet ingestion
Every client connects over a dedicated private circuit with its own isolation. There is no public-internet ingestion path, not even as a fallback.
Provability
Every object and decision carries cryptographic evidence: hashed on arrival, chained, timestamped by an accredited third party and, from Assurance, publicly anchored. Audit preparation becomes an export, not weeks of reconstruction.
Sovereignty
You hold the keys. Primary copies stay in the UK. The cross-border recovery copy is encrypted in the UK under keys that remain in your control before it is written to tape in São Paulo. Erasure is cryptographic before it is contractual.
Cyber-resilience
When ransomware reaches your backups, an encrypted air-gapped copy is the line cloud backups alone do not give you.
Your regulator no longer asks for policy theatre. It asks for proof.
UK operational resilience has moved from statements to enforcement. The reporting regime from March 2027 brings your supply chain into the same supervisory lens. The question is not whether you hold controls. It is whether you can evidence them before, during and after an incident, including when the supplier chain itself is hit.
Operational resilience
FCA PS21/3 and PRA SS1/21: map important business services, set impact tolerances and show you can stay within them. Recovery drills and restores become sealed events with verifiable dates and integrity.
Incident and third-party reporting
FCA PS26/2 and PRA PS7/26 create a co-ordinated regime across FCA, PRA and the Bank of England. Firms must report qualifying operational incidents and notify material third-party arrangements. Every custody event is already a record; heimr supplies its own notification pack.
Model risk
PRA SS1/23 centres on identification, independent validation and documented governance. Proving which model produced which decision, on which data, is an evidence problem. The MRM Decision Record captures model artefact hash, dataset manifest and decision context.
Proof that does not depend on trusting heimr.
Four steps. One per tier. Each step reduces the trust you would otherwise place in heimr, until the last, where it is no longer required.
Hashed on arrival
Fingerprinted when it reaches us and, with the SDK, inside your environment before it leaves.
Third-party timestamps
RFC 3161 on manifests by an accredited time-stamping authority. The date is attested independently.
Ledger and public anchor
Append-only ledger with Merkle trees; root anchored daily to an external public record. Nothing is quietly altered, including by us.
Independent verification
An expert confirms the full chain from the evidence pack and public anchor, with no access to heimr systems.
Trust profile is configurable. Timestamps under ICP-Brasil, eIDAS or a UK-regime provider, selected per tenant; evidence format stays the same.
Managed custody
Ingestion, verification, retention policy and air-gap operations run by heimr. No hardware, no capital build, no specialist headcount on your side.
Evidence portal
Custody-chain timeline and one-click evidence packs in formats auditors and regulators already accept.
Ingestion SDK
Drops into your pipelines; MLflow connector records which model decided what, on which data.
Open verifier
Public tool. Any third party checks evidence without depending on heimr.
What crosses the border, and what never does
Primary custody is in-country: both live vaults in IBM Cloud London. The only data that crosses a border is the recovery copy, encrypted in the UK under UK-held keys, then written to air-gapped tape in São Paulo. The ledger carries hashes and manifests, never readable content. At Deep Archive the tape copy is the custody copy under the same encryption and key-control conditions.
UK GDPR: a standard mechanism, engineered to be strong
Transfers to Brazil under the IDTA or UK Addendum to the EU SCCs, with a documented Transfer Risk Assessment delivered at onboarding for your DPO. Encryption before transfer, UK-held keys and cryptographic erasure strengthen that assessment. Brazil is not on the UK adequacy list today; the safeguards do not depend on it being there.
FCA / PRA outsourcing: designed for the rulebook
Offshore storage is permitted and regulated. Contracts guarantee unrestricted audit and access for you and your regulators, full portability and a tested exit strategy (FG16/5, SYSC 8, SS2/21). Due diligence questionnaires are answered with documents we already maintain.
The European bridge
EU to UK adequacy renewed to December 2031; EU and Brazil mutual adequacy from January 2026. If you serve EEA customers, heimr operates at both ends of that free-flow area. EU AI Act high-risk duties for Annex III systems take effect 2 December 2027, and the record-keeping is a custody problem.
If the data feeds a GPU or answers a live query, it is not for the vault. If it is large, cold, must last for years and needs air-gap or regulatory proof, that is the typical case.
Architecture session
30 minutes on retention estate, transfer risk and recovery posture. Technical, direct, no commitment.
Scoped proof of value
One retention estate or model pipeline under custody. You export a real evidence pack and put it in front of your auditor.
Production onboarding
SDK into pipelines, retention policies codified, transfer documentation delivered, first air-gap cycle executed and sealed, as a managed service.
At Deep Archive the path is shorter: scope, circuit provisioning and first estate under custody.
Resilience stopped being only an IT topic. It became something you must be able to demonstrate.
If your regulator asked tomorrow for proof that a record existed, when it existed and that nothing altered it, how long would you need to answer?