:: Sovereign Vault · London

Custody you can prove. Recovery that survives the incident.

Sovereign Vault holds what your firm must retain and delivers the evidence ready, in forms your auditor, regulator and a court already accept. Four tiers of service. Start with what you need and scale without changing supplier, contract or architecture.

ISO/IEC 27001 certified · IBM partner · London (Level39, Canary Wharf) & São Paulo
:: Four tiers. One architecture. One contract.

Start with what you need today. Scale without a migration project.

The architecture is identical across all four tiers. What changes is how far the proof reaches, and how much trust in heimr it still requires. Moving up a tier is a commercial decision, not a platform change.

Tier 1 · Entry

Deep Archive

Your cold estate on tape, physically off the network, with a monthly receipt that evidences integrity object by object.

Delivery over S3 or SFTP across a dedicated private circuit. Hashed on arrival. Written to an IBM Diamondback tape library in a physically segregated facility, catalogued by media, position and manifest.

Recovery is by tape recall, measured in hours. Right for cold estates that must last and must be provable.
Tier 2

Custody

Answer a supervisory request inside the deadline, with the date attested by an accredited third party.

Adds the Regulatory Vault and Sovereign Archive in the cloud: object lock in compliance mode, per-object retention and legal hold, RFC 3161 timestamps on manifests, plus a portal with searchable catalogue and access trail.

From here, the date is attested by an authority independent of heimr.
Tier 3

Assurance

The proof still stands even if heimr itself is compromised.

Adds an append-only evidence ledger with Merkle trees, daily anchoring of the root to an external public record, PAdES/CAdES evidence packs, and the Cyber Recovery Vault on air-gap separate from the cloud plane, with clean-room recovery exercises and a signed report.

Tier 4

Sovereign+

Any expert verifies your evidence unaided, without asking heimr for anything.

Adds the public open-source verifier, customer-held keys in a dedicated HSM, hybrid post-quantum signatures alongside the classical chain, and scheduled evidence renewal before algorithms age out.

For proof that must still stand in twenty years.

Deep Archive starts with a single estate. Higher tiers are sized by volume and retention profile.

At Deep Archive the custody copy sits on tape in São Paulo: another continent, offline, out of reach of anything that compromises your UK estate. IDTA or UK Addendum plus a Transfer Risk Assessment come with onboarding, not as a billed project. If your policy requires primary custody in the UK, start at Custody instead.

:: 30 minutes

In 30 minutes, find out which tier you are on.

A working conversation about your estate: what must be retained, for how long, under which rules, and what you could not evidence today if asked.

Book a conversation
:: Where your data sits
Primary custody

London, United Kingdom

Regulatory Vault and Sovereign Archive on enterprise object storage in the IBM Cloud London region. Primary copies remain in the UK, under UK jurisdiction.

Air-gapped cyber recovery

São Paulo, Brazil

Encrypted offline copy on a dedicated IBM Diamondback tape library in a physically segregated facility, dual control, every open and close recorded as a custody event. This is recovery capacity, not a claim of UK data sovereignty in Brazil.

Data path

No public internet ingestion

Every client connects over a dedicated private circuit with its own isolation. There is no public-internet ingestion path, not even as a fallback.

01

Provability

Every object and decision carries cryptographic evidence: hashed on arrival, chained, timestamped by an accredited third party and, from Assurance, publicly anchored. Audit preparation becomes an export, not weeks of reconstruction.

02

Sovereignty

You hold the keys. Primary copies stay in the UK. The cross-border recovery copy is encrypted in the UK under keys that remain in your control before it is written to tape in São Paulo. Erasure is cryptographic before it is contractual.

03

Cyber-resilience

When ransomware reaches your backups, an encrypted air-gapped copy is the line cloud backups alone do not give you.

:: The UK regulatory reality

Your regulator no longer asks for policy theatre. It asks for proof.

UK operational resilience has moved from statements to enforcement. The reporting regime from March 2027 brings your supply chain into the same supervisory lens. The question is not whether you hold controls. It is whether you can evidence them before, during and after an incident, including when the supplier chain itself is hit.

In force since March 2025

Operational resilience

FCA PS21/3 and PRA SS1/21: map important business services, set impact tolerances and show you can stay within them. Recovery drills and restores become sealed events with verifiable dates and integrity.

Applies from 18 March 2027

Incident and third-party reporting

FCA PS26/2 and PRA PS7/26 create a co-ordinated regime across FCA, PRA and the Bank of England. Firms must report qualifying operational incidents and notify material third-party arrangements. Every custody event is already a record; heimr supplies its own notification pack.

Effective 17 May 2024

Model risk

PRA SS1/23 centres on identification, independent validation and documented governance. Proving which model produced which decision, on which data, is an evidence problem. The MRM Decision Record captures model artefact hash, dataset manifest and decision context.

:: The evidence chain

Proof that does not depend on trusting heimr.

Four steps. One per tier. Each step reduces the trust you would otherwise place in heimr, until the last, where it is no longer required.

01Deep Archive

Hashed on arrival

Fingerprinted when it reaches us and, with the SDK, inside your environment before it leaves.

02Custody

Third-party timestamps

RFC 3161 on manifests by an accredited time-stamping authority. The date is attested independently.

03Assurance

Ledger and public anchor

Append-only ledger with Merkle trees; root anchored daily to an external public record. Nothing is quietly altered, including by us.

04Sovereign+

Independent verification

An expert confirms the full chain from the evidence pack and public anchor, with no access to heimr systems.

Trust profile is configurable. Timestamps under ICP-Brasil, eIDAS or a UK-regime provider, selected per tenant; evidence format stays the same.

Public open-source verifier · Sovereign+ Crypto-shredding: UK GDPR erasure without breaking the chain · Custody and above Hybrid ML-DSA signatures, ML-KEM transport · Sovereign+ Evidence renewal under ERS/RFC 4998 and PAdES-LTA · Sovereign+
:: The service at a glance

Managed custody

Ingestion, verification, retention policy and air-gap operations run by heimr. No hardware, no capital build, no specialist headcount on your side.

Evidence portal

Custody-chain timeline and one-click evidence packs in formats auditors and regulators already accept.

Custody and above

Ingestion SDK

Drops into your pipelines; MLflow connector records which model decided what, on which data.

Sovereign+

Open verifier

Public tool. Any third party checks evidence without depending on heimr.

:: For your CISO and your DPO

What crosses the border, and what never does

Primary custody is in-country: both live vaults in IBM Cloud London. The only data that crosses a border is the recovery copy, encrypted in the UK under UK-held keys, then written to air-gapped tape in São Paulo. The ledger carries hashes and manifests, never readable content. At Deep Archive the tape copy is the custody copy under the same encryption and key-control conditions.

UK GDPR: a standard mechanism, engineered to be strong

Transfers to Brazil under the IDTA or UK Addendum to the EU SCCs, with a documented Transfer Risk Assessment delivered at onboarding for your DPO. Encryption before transfer, UK-held keys and cryptographic erasure strengthen that assessment. Brazil is not on the UK adequacy list today; the safeguards do not depend on it being there.

FCA / PRA outsourcing: designed for the rulebook

Offshore storage is permitted and regulated. Contracts guarantee unrestricted audit and access for you and your regulators, full portability and a tested exit strategy (FG16/5, SYSC 8, SS2/21). Due diligence questionnaires are answered with documents we already maintain.

The European bridge

EU to UK adequacy renewed to December 2031; EU and Brazil mutual adequacy from January 2026. If you serve EEA customers, heimr operates at both ends of that free-flow area. EU AI Act high-risk duties for Annex III systems take effect 2 December 2027, and the record-keeping is a custody problem.

:: Where Sovereign Vault applies
Regulatory audits & skilled person reviews M&A due diligence Litigation & disclosure Post-ransomware recovery AI & model accountability Long-term retention (7–25 years) Material third-party register (PS26/2 / PS7/26) EU AI Act · Annex III, December 2027

If the data feeds a GPU or answers a live query, it is not for the vault. If it is large, cold, must last for years and needs air-gap or regulatory proof, that is the typical case.

:: How an engagement starts
01

Architecture session

30 minutes on retention estate, transfer risk and recovery posture. Technical, direct, no commitment.

02

Scoped proof of value

One retention estate or model pipeline under custody. You export a real evidence pack and put it in front of your auditor.

03

Production onboarding

SDK into pipelines, retention policies codified, transfer documentation delivered, first air-gap cycle executed and sealed, as a managed service.

At Deep Archive the path is shorter: scope, circuit provisioning and first estate under custody.

Resilience stopped being only an IT topic. It became something you must be able to demonstrate.

If your regulator asked tomorrow for proof that a record existed, when it existed and that nothing altered it, how long would you need to answer?

Book a conversation

Talk to us
Explore our solutions

LONDON

LEVEL39, One Canada Square, Canary Wharf, 39th floor
London, E14 5AB
UNITED KINGDOM

SAO PAULO

WTC, Av. das Nações Unidas, 12551, 24o andar
Brooklin, São Paulo
BRAZIL