# Kvelden Docs - [Introduction](https://docs.kvelden.com/introduction.md): Kvelden builds precision cybersecurity infrastructure. This is the documentation for Enclave — our encrypted collaboration platform with client-controlled keys and zero-knowledge rooms. - [Core Concepts](https://docs.kvelden.com/concepts.md): The foundational ideas behind Enclave — rooms, encryption, keys, and access control. - [Quickstart](https://docs.kvelden.com/quickstart.md): Get your team into Enclave in under 10 minutes. - [Deployment Overview](https://docs.kvelden.com/deployment/overview.md): Choose how and where to run Enclave — from a fully-managed SaaS to a fully air-gapped on-premise appliance. In every model, Kvelden never holds your keys. - [SaaS Deployment](https://docs.kvelden.com/deployment/saas.md): Kvelden-hosted Enclave — zero infrastructure, same security guarantees. - [Private Cloud (VPC)](https://docs.kvelden.com/deployment/private-cloud.md): Deploy Enclave inside your own cloud account — your VPC, your network perimeter. - [On-Premise Deployment](https://docs.kvelden.com/deployment/on-premise.md): Run Enclave entirely within your own data centre. - [Air-Gapped Deployment](https://docs.kvelden.com/deployment/air-gapped.md): Enclave with no external network connectivity — for classified and highly regulated environments. - [Private Virtual Appliance](https://docs.kvelden.com/deployment/private-appliance.md): Deploy Kvelden Enclave inside your own infrastructure as a pre-packaged OVA — your network perimeter, your keys, your data. - [First-run setup](https://docs.kvelden.com/deployment/appliance/first-run.md): Bring a freshly deployed Enclave appliance online — console access, SSH key enrolment, the first account, and network configuration. - [Web TLS certificate & hostname](https://docs.kvelden.com/deployment/appliance/tls.md): Give the appliance a hostname and install a trusted TLS certificate so browsers show a secure padlock instead of a warning. - [LDAP / Active Directory sign-in](https://docs.kvelden.com/deployment/appliance/ldap.md): Let users sign in to the appliance with their existing LDAP or Active Directory credentials, alongside local accounts and SSO. - [Licensing & Activation](https://docs.kvelden.com/deployment/appliance/licensing.md): Activate your Enclave appliance with the licence issued by Kvelden, and understand trial, renewal, and expiry behaviour. - [KMS Configuration](https://docs.kvelden.com/deployment/appliance/kms.md): Configure the Key Management System that the Enclave appliance uses to wrap and unwrap file encryption keys — required before users can upload files. - [Storage Configuration](https://docs.kvelden.com/deployment/appliance/storage.md): Configure where the Enclave appliance stores encrypted file data — S3-compatible object storage, NFS, or local disk. - [High availability & clustering](https://docs.kvelden.com/deployment/appliance/clustering.md): Join two or more Enclave appliances into a single high-availability cluster with automatic failover, synchronous replication (RPO 0), and a stable ingress address — configurable entirely from the admin GUI or the console. - [System upgrade](https://docs.kvelden.com/deployment/appliance/upgrade/overview.md): How to upgrade the Kvelden Enclave appliance to a new release from the admin GUI — a signed, verified, self-healing update with automatic rollback. Standalone appliances update in place with a brief reboot; clusters roll one node at a time with zero downtime. - [Standalone upgrade (GUI)](https://docs.kvelden.com/deployment/appliance/upgrade/standalone.md): Step-by-step guide to upgrading a single (non-clustered) Kvelden Enclave appliance to a new release from the admin GUI. Signed and verified, with a brief reboot and automatic rollback if the new version is unhealthy. - [Cluster in-place upgrade (GUI)](https://docs.kvelden.com/deployment/appliance/upgrade/cluster.md): Step-by-step guide to upgrading a Kvelden Enclave cluster to a new release from the admin GUI with zero downtime — one node at a time, standbys first and the primary last, with automatic bundle distribution, per-node readiness checks, and automatic rollback of any node that fails. - [Platform Storage Configuration](https://docs.kvelden.com/deployment/platform-storage.md): Configure the shared S3 storage backend that the Enclave appliance uses to store encrypted files for all tenants. - [Enclave Overview](https://docs.kvelden.com/enclave/overview.md): Encrypted collaboration with keys you control and zero-knowledge rooms, for teams that handle sensitive data. - [Rooms](https://docs.kvelden.com/enclave/rooms.md): Secure encrypted workspaces for your team. - [Encryption](https://docs.kvelden.com/enclave/encryption.md): How Enclave encrypts your files — on your device, before upload. - [Access Control](https://docs.kvelden.com/enclave/access-control.md): Role-based and attribute-based access control in Enclave — membership, clearance, and sharing policies. - [Data Sharing Policies](https://docs.kvelden.com/enclave/sharing-policies.md): Three-tier policy cascade that controls who can share files, to whom, and under what conditions. - [Data Loss Prevention (DLP)](https://docs.kvelden.com/enclave/dlp.md): Content-scanning policies that detect and act on sensitive data patterns at upload time. - [Security Alerts](https://docs.kvelden.com/enclave/security-alerts.md): Real-time alerting for critical audit events and behavioral anomalies across authentication, files, rooms, users, DLP, KMS, and storage. - [Audit Logs](https://docs.kvelden.com/enclave/audit-logs.md): Every access event in Enclave is logged, timestamped, and cryptographically signed. - [Webhooks](https://docs.kvelden.com/enclave/webhooks.md): Real-time HTTP delivery of Enclave audit events — configure endpoints, verify signatures, and integrate with SIEMs and automation tools. - [Password-Protected PDFs](https://docs.kvelden.com/enclave/password-protected-pdfs.md): How Enclave handles PDF files that require an open password — at upload, during scanning, and in the browser viewer. - [Compliance](https://docs.kvelden.com/enclave/compliance.md): SOC 2, ISO 27001, GDPR, HIPAA, and more — how Enclave supports your compliance posture. - [Key Management](https://docs.kvelden.com/enclave/key-management.md): Connect your own KMS, provision CMKs, run key health checks, and manage encryption policies — all without Kvelden ever holding your master keys. - [AWS KMS](https://docs.kvelden.com/enclave/kms/aws-kms.md): Connect AWS KMS as a BYOK provider — configure cross-account IAM Role or static credentials to let Enclave wrap and unwrap file encryption keys using your Customer Managed Key. - [Thales CipherTrust](https://docs.kvelden.com/enclave/kms/thales-ciphertrust.md): Connect Thales CipherTrust Manager as a HYOK provider via KMIP over mutual TLS — Enclave never holds your HSM admin credentials or master key material. - [Storage](https://docs.kvelden.com/enclave/storage.md): Keep file data inside your own infrastructure with Bring Your Own Storage (BYOS). Enclave handles all encryption, access control, and key management — your backend receives only ciphertext. - [AWS S3](https://docs.kvelden.com/enclave/storage/aws-s3.md): Connect an AWS S3 bucket as your Bring Your Own Storage backend using cross-account IAM Role assumption or static credentials. - [MinIO](https://docs.kvelden.com/enclave/storage/minio.md): Connect a self-hosted MinIO instance as a Bring Your Own Storage backend. MinIO is fully S3-compatible and supports Enclave's presigned upload pipeline. - [Organisation Overview](https://docs.kvelden.com/organization/overview.md): Managing your Kvelden Enclave organisation — users, Org Units, policies, and access reviews. - [Authentication](https://docs.kvelden.com/organization/authentication.md): How users sign in to Enclave — local accounts, enterprise SSO (OIDC and SAML 2.0), LDAP / Active Directory, and external guest verification — with configuration steps for each. - [SSO with Okta](https://docs.kvelden.com/organization/sso/okta.md): Step-by-step guide to connect Okta to Enclave for enterprise single sign-on, using either SAML 2.0 or OIDC — including the exact field mappings, SP certificate setup, and troubleshooting. - [SSO with Microsoft Entra ID](https://docs.kvelden.com/organization/sso/entra-id.md): Connect Microsoft Entra ID (Azure AD) to Enclave for enterprise single sign-on via OIDC or SAML 2.0, with the exact field mappings and Entra-specific notes. - [SSO with Google Workspace](https://docs.kvelden.com/organization/sso/google-workspace.md): Connect Google Workspace to Enclave for enterprise single sign-on via OIDC or a custom SAML app, with the exact field mappings. - [SSO with a custom IdP](https://docs.kvelden.com/organization/sso/custom.md): Connect any OpenID Connect or SAML 2.0 identity provider to Enclave — the generic field mappings that apply to Ping, ADFS, Auth0, Keycloak, OneLogin, and others. - [Users](https://docs.kvelden.com/organization/users.md): Inviting, managing, disabling, offboarding, and removing users in your Enclave organisation. - [Roles & Permissions](https://docs.kvelden.com/organization/roles.md): A complete reference of what each Enclave role can do — fixed system roles with no per-user customisation. - [Org Units](https://docs.kvelden.com/organization/org-units.md): Flexible, hierarchical groupings that control room access and data-sharing scope in Enclave. - [Clearance Levels](https://docs.kvelden.com/organization/clearance.md): Classification-based access control — users need both room membership and sufficient clearance. - [Security Architecture](https://docs.kvelden.com/security/architecture.md): How Enclave is built to be secure by design, not by promise. - [Cryptographic Primitives](https://docs.kvelden.com/security/cryptography.md): The exact algorithms and parameters Enclave uses — no marketing, just the spec. - [Zero-Knowledge Design](https://docs.kvelden.com/security/zero-knowledge.md): What zero-knowledge means in Enclave — and what it doesn't. - [Key Recovery](https://docs.kvelden.com/security/key-recovery.md): Recover access to a Zero-Knowledge or ZK Strict room after a forgotten passphrase — or when the person who holds the key is unavailable. Both paths are customer-controlled; neither gives Kvelden the ability to read your rooms.