Overview
The SaaS deployment is hosted and operated by Kvelden. You get the full Enclave security model without managing any infrastructure. The encryption model is identical to self-hosted deployments. Your master key lives in your own KMS, or in Kvelden’s HSM for platform-managed keys — Kvelden never stores it in plaintext. Because Kvelden operates the servers, Envelope-encrypted and personal files can be decrypted server-side to serve your downloads and the workflows you enable (DLP, signing); for content Kvelden can never read, use Zero-Knowledge / ZK-Strict rooms, where the key stays only on your devices. (In self-hosted/appliance models Kvelden operates nothing and has no access at all.)What Kvelden manages
- Server infrastructure and uptime
- TLS certificates and renewal
- Security patching and updates
- Database backups
- HSM operations (if using Kvelden-managed keys)
What you control
- User and Org Unit management
- Room creation and membership
- Encryption keys (BYOK/HYOK optional)
- Audit log exports
- Data retention settings
SLA
Data residency
Choose your region at signup:- India (Mumbai) — default for Indian customers
- EU (Frankfurt) — GDPR-aligned
- US East (Virginia)
- US West (Oregon)
- Singapore