Agent-first data protection · Software-key sandbox · HSM custody options

Data protection that
humans authorize,
agents execute.

Cloak encrypts files, manages software-sandbox or HSM-backed keys, applies DRM policy, and signs documents — automatically, on behalf of your team and your AI agents. File encryption and KMS key operations return signed audit receipts today; Vault and Batchsign receipts are coming.

Protection receipt · verified
{
  "actor":      "claude-desktop / agent-session-A7F2",
  "operation":  "file_protected",
  "file_type":  "pdf",
  "policy":     "professional-workspace-v2",
  "key_ref":    "kms://kms.cloakapps.com/keys/k-9a3b",
  "timestamp":  "2026-04-30T09:14:22Z",
  "receipt_id": "rcpt_4xKmP9vLq2Yw",
  "signature":  "MEYCIQDx4... (AATL)",
  "verify_url": "https://cloakapps.com/verify/rcpt_4xKmP9vLq2Yw"
}

Cloak Files and Cloak KMS operations produce a tamper-evident signed receipt — human or agent. Vault and Batchsign receipts coming soon.

Built for professional workflows that can't afford a breach

The same friction that stopped file encryption before — agents remove it entirely.

📊

Accountants

Protect client tax files, payroll records, and PII automatically during collection season. Agent classifies, encrypts, and receipts — human approves policy once.

Cloak Files →
⚖️

Legal Teams

Protect privileged documents before upload, email, or AI review. DRM controls who reads, prints, or forwards. Receipts prove chain of custody.

Cloak Vault →
⚙️

DevSecOps

Give AI coding agents scoped signing and key operations without exposing raw secrets. Start in the software sandbox; move to HSM custody when needed.

Cloak KMS →
🏦

Finance & Compliance

Agent-assisted approval workflows, AATL-signed PDFs, and controlled document release with full human oversight and audit logs that satisfy regulators.

Batchsign →

One protection family. Four products.

Each product solves a specific problem. Together, they cover the full data protection workflow.

Integration story

Cloak Files + Cloak KMS = HSM-Protected Workspace

Start with Cloak Files for file protection and a SoftHSM sandbox key for development. When keys must never leave hardware, try a smartcard HSM, then move to YubiHSM 2, AWS CloudHSM, or BYO HSM for regulated industries, enterprise compliance, or AI agents that need cryptographic trust anchors. Same API, same receipts, stronger custody path — with consultation available if you'd like a hand.

How an agent-protected workflow runs

Six steps from request to verified receipt. Humans set policy once; agents operate within it.

01

Request

Human or agent asks to protect a file, key, PDF, or signing task. Natural language or structured JSON.

02

Classify

Local AI classifies the data sensitivity and recommends the protection policy. No content leaves the network.

03

Authorize

Human approves budget, policy, and any sensitive operation outside pre-approved scope.

04

Execute

Agent calls Cloak Files or Cloak KMS APIs (Vault and Batchsign agent surfaces coming soon). Operations run inside approved policy.

05

Receipt

System returns a signed JSON/PDF audit receipt with actor, policy, key reference, timestamp, and verification URL.

06

Lifecycle

Revoke, rotate, re-sign, reclassify, or export audit logs. Policy evolves; receipts remain verifiable.

Agent-first interfaces

Cloak Files and Cloak KMS are MCP-callable today

AI agents — Claude, Cursor, AutoGen, your own pipelines — can call Cloak Files and Cloak KMS directly using the Model Context Protocol. Cloak Vault and Batchsign MCP surfaces are coming next. No API key gymnastics. Scoped credentials with expiry, rotation, revocation, and a full audit trail per session.

  • MCP server for KMS key management, signing, encryption, and ECDH derive — 9 live tools
  • Scoped agent credentials with expiry, rotation, and per-tool permissions
  • Machine-readable /.well-known/mcp.json and llms.txt for agent discovery
  • Embedded signed receipts on every state-changing op — verify offline at verify.cloakapps.com
Full agent integration guide →
// MCP tool call — Claude agent signing a digest with a KMS key
kms_sign(
alias: "agent-signing-key",
keyId: "0101",
algorithm: "ECDSA_SHA_256",
digestHex: "a4caf7bd…21083d95"
)
// Returns (receipt embedded by default):
{
"signatureBase64": "MEYCIQDx9n…",
"receipt": { "payload": "…", "signature": "…" },
"verify_at": "https://cloakapps.com/verify.html"
}

Simple, honest pricing

Start free. Pay when you protect things that matter.

Free Developer

$0 / month

CLI, SDK, Agentic AI (MCP) in a SoftHSM software-key sandbox, sample receipts. Strict limits — not for production.

Start free
Most popular

Protected Workspace

$199 / month

Smartcard HSM custody, up to 10 keys, unlimited file ops, and Agentic AI (MCP) on all your keys. One account.

Start free →

Enterprise Gateway

$799 / team/month

Cloak Gateway with your user-owned HSM devices, up to 50 keys, 5 seats, Agentic AI, and consultative setup.

Book a consultation →

Enterprise HSM & signing from $2,000/month. View all plans →

OMMAU governance

Data protection you can trust. For humans and agents.

Cloak publishes a public governance charter: three filters every product decision and every agent operation passes through. Data sovereignty, equal agent access, and verifiable societal benefit — not marketing language, operational constraints.

  • 🔐
    Data sovereignty
    You control keys, policies, exports, retention, and deletion. Always.
  • 👤
    Human accountability
    Humans authorize budgets, enterprise policies, and privileged operations. Agents operate within granted scope.
  • 🤝
    Agent equality
    Stable, auditable interfaces for AI agents — same capabilities as humans, explicit granted authority.
Read the full charter →
No key exfiltration

No support agent, sales agent, or external service accesses raw key material or decrypted customer content.

Abuse resistance

Use cases involving malware, credential theft, non-consensual surveillance, or evasion of lawful access are blocked.

Transparency

Every protected operation produces an audit receipt understandable by both humans and machines.

Start protecting your data today.

Free developer tier starts in a SoftHSM software-key sandbox. Try a smartcard HSM, then move to YubiHSM 2, AWS CloudHSM, or BYO HSM — with consultation and integration assistance for enterprises and businesses.

Cloak Pte. Ltd. · Paya Lebar Square #06-28 · Singapore 409051 · sales@cloakapps.com