Across all models, files are encrypted with keys you control, and
Zero-Knowledge / ZK-Strict rooms are undecryptable by the server. In
self-hosted / appliance models Kvelden operates nothing and has no access at
all; in SaaS, Kvelden-operated servers can decrypt Envelope/personal files
server-side to serve your downloads and enabled workflows. The deployment model
changes where the servers, storage, and keys physically reside.
Choose a deployment model
SaaS (Cloud)
Kvelden-hosted and fully managed. Zero infrastructure to run — the fastest way to get started.
Private Cloud (VPC)
Enclave deployed inside your own cloud account and VPC. Your network perimeter, your storage.
On-Premise
Run Enclave entirely within your own data centre, under your operational control.
Air-Gapped
No external network connectivity — for classified, regulated, and sovereign environments.
Comparison
On-premise and air-gapped deployments ship as the Private Virtual Appliance (OVA) — a signed, pre-packaged image you import into your own virtualization platform.
The Private Virtual Appliance (OVA)
The self-hosted models are delivered as a hardened OVA you import into VMware, Hyper-V, or KVM. After importing, you complete a guided setup for networking, TLS, identity, licensing, keys, and storage.Appliance Overview
What the OVA contains, sizing, and the import process.
First-Run Setup
The guided first-boot wizard: hostname, admin account, and initial configuration.
TLS Certificates
Install your own TLS certificate or use the built-in certificate authority.
LDAP / Active Directory
Connect the appliance to your directory for single sign-on.
Licensing
Activate the appliance with a signed offline license — no phone-home required.
Key Management
Set the appliance-wide KMS: the built-in master key, or your own HSM via KMIP.
Before you begin
Regardless of model, have the following ready:- Owner access to complete the initial setup
- Your identity provider details (if using LDAP / Active Directory SSO)
- Your KMS or HSM connection details if you intend to bring your own keys — see Key Management
- Your object storage details (bucket, region, credentials) for self-hosted models — see Storage