Your keys stay yours
Private keys live in your HSM or the signing provider you choose. Alloy holds no customer private keys.
Security & trust
Alloy is software you run inside your own environment, not a service where you park assets. Your risk profile, your data and your keys stay where your regulators expect them.
How it is built
Private keys live in your HSM or the signing provider you choose. Alloy holds no customer private keys.
Deploy to your own cloud account or data center, behind your network, identity and monitoring controls.
Requests, policy decisions and status changes are recorded and can be exported for audit and regulatory review.
Roles for your people and scoped API keys for your services and agents, each with only the permissions it needs.
Security review
No. Alloy is software you operate. It holds no customer private keys and never takes possession of assets.
In your own environment. Alloy runs in your cloud account or data center, so transaction data stays inside your perimeter.
Not by default. Your deployment runs in infrastructure you control, and access is granted on your terms.
We walk your security and risk teams through where keys, data and decisions live, and share architecture and data-flow documentation for your review.
Tell us what your review needs and we will walk your team through it.