Skip to main content
Enclave runs the same platform across every deployment model. What changes is where the infrastructure lives and who operates it — not the encryption model. Pick the model that matches your compliance, data-residency, and network-isolation requirements.
Across all models, files are encrypted with keys you control, and Zero-Knowledge / ZK-Strict rooms are undecryptable by the server. In self-hosted / appliance models Kvelden operates nothing and has no access at all; in SaaS, Kvelden-operated servers can decrypt Envelope/personal files server-side to serve your downloads and enabled workflows. The deployment model changes where the servers, storage, and keys physically reside.

Choose a deployment model

SaaS (Cloud)

Kvelden-hosted and fully managed. Zero infrastructure to run — the fastest way to get started.

Private Cloud (VPC)

Enclave deployed inside your own cloud account and VPC. Your network perimeter, your storage.

On-Premise

Run Enclave entirely within your own data centre, under your operational control.

Air-Gapped

No external network connectivity — for classified, regulated, and sovereign environments.

Comparison

On-premise and air-gapped deployments ship as the Private Virtual Appliance (OVA) — a signed, pre-packaged image you import into your own virtualization platform.

The Private Virtual Appliance (OVA)

The self-hosted models are delivered as a hardened OVA you import into VMware, Hyper-V, or KVM. After importing, you complete a guided setup for networking, TLS, identity, licensing, keys, and storage.

Appliance Overview

What the OVA contains, sizing, and the import process.

First-Run Setup

The guided first-boot wizard: hostname, admin account, and initial configuration.

TLS Certificates

Install your own TLS certificate or use the built-in certificate authority.

LDAP / Active Directory

Connect the appliance to your directory for single sign-on.

Licensing

Activate the appliance with a signed offline license — no phone-home required.

Key Management

Set the appliance-wide KMS: the built-in master key, or your own HSM via KMIP.

Before you begin

Regardless of model, have the following ready:
  • Owner access to complete the initial setup
  • Your identity provider details (if using LDAP / Active Directory SSO)
  • Your KMS or HSM connection details if you intend to bring your own keys — see Key Management
  • Your object storage details (bucket, region, credentials) for self-hosted models — see Storage
Once deployed, continue to the Platform Guide to configure secure rooms, encryption policies, and access control.