Agent-first data protection · HSM-backed keys · Signed audit receipts

Data protection that
humans authorize,
agents execute.

Cloak encrypts files, manages HSM-backed keys, applies DRM policy, and signs documents — automatically, on behalf of your team and your AI agents. Every operation returns a signed audit receipt.

Protection receipt · verified
{
  "actor":      "claude-desktop / agent-session-A7F2",
  "operation":  "file_protected",
  "file_type":  "pdf",
  "policy":     "professional-workspace-v2",
  "key_ref":    "hsm://kms.cloakapps.com/keys/k-9a3b",
  "timestamp":  "2026-04-30T09:14:22Z",
  "receipt_id": "rcpt_4xKmP9vLq2Yw",
  "signature":  "MEYCIQDx4... (AATL)",
  "verify_url": "https://cloakapps.com/verify/rcpt_4xKmP9vLq2Yw"
}

Every protection operation — human or agent — produces a tamper-evident signed receipt.

Built for professional workflows that can't afford a breach

The same friction that stopped file encryption before — agents remove it entirely.

📊

Accountants

Protect client tax files, payroll records, and PII automatically during collection season. Agent classifies, encrypts, and receipts — human approves policy once.

Cloak Files →
⚖️

Legal Teams

Protect privileged documents before upload, email, or AI review. DRM controls who reads, prints, or forwards. Receipts prove chain of custody.

Cloak Vault →
⚙️

DevSecOps

Give AI coding agents HSM-backed signing and key operations without exposing raw secrets. MCP interface, scoped credentials, audit logs, key rotation.

Cloak KMS →
🏦

Finance & Compliance

Agent-assisted approval workflows, AATL-signed PDFs, and controlled document release with full human oversight and audit logs that satisfy regulators.

Batchsign →

One protection family. Four products.

Each product solves a specific problem. Together, they cover the full data protection workflow.

Integration story

Cloak Files + Cloak KMS = HSM-Protected Workspace

Start with Cloak Files for file protection. Upgrade to the HSM-Protected Workspace when keys must never leave hardware — for regulated industries, enterprise compliance, or AI agents that need cryptographic trust anchors. Same API, same receipts, keys now backed by real HSM hardware.

How an agent-protected workflow runs

Six steps from request to verified receipt. Humans set policy once; agents operate within it.

01

Request

Human or agent asks to protect a file, key, PDF, or signing task. Natural language or structured JSON.

02

Classify

Local AI classifies the data sensitivity and recommends the protection policy. No content leaves the network.

03

Authorize

Human approves budget, policy, and any sensitive operation outside pre-approved scope.

04

Execute

Agent calls Cloak Files, KMS, Vault, or Batchsign APIs. Operations run inside approved policy.

05

Receipt

System returns a signed JSON/PDF audit receipt with actor, policy, key reference, timestamp, and verification URL.

06

Lifecycle

Revoke, rotate, re-sign, reclassify, or export audit logs. Policy evolves; receipts remain verifiable.

Agent-first interfaces

Every Cloak product is MCP-callable

AI agents — Claude, Cursor, AutoGen, your own pipelines — can call Cloak tools directly using the Model Context Protocol. No API key gymnastics. Scoped credentials with expiry, rotation, revocation, and a full audit trail per session.

  • MCP server for HSM key management, signing, encryption, and ECDH derive — 9 live tools
  • Scoped agent credentials with expiry, rotation, and per-tool permissions
  • Machine-readable /.well-known/mcp.json and llms.txt for agent discovery
  • Embedded signed receipts on every state-changing op — verify offline at verify.cloakapps.com
Full agent integration guide →
// MCP tool call — Claude agent signing a digest with an HSM key
kms_sign(
alias: "agent-signing-key",
keyId: "0101",
algorithm: "ECDSA_SHA_256",
digestHex: "a4caf7bd…21083d95"
)
// Returns (receipt embedded by default):
{
"signatureBase64": "MEYCIQDx9n…",
"receipt": { "payload": "…", "signature": "…" },
"verify_at": "https://cloakapps.com/verify.html"
}

Simple, honest pricing

Start free. Pay when you protect things that matter.

Developer Free

$0 / month

CLI, SDK, MCP demo, test keys, sample receipts. Strict limits — not for production.

Start free
Most popular

Professional

$199 / team/month

File protection, PDF policy, receipts, dashboard, email support. For accountants, lawyers, consultants.

Start trial →

Agent API

$799 / team/month

MCP access, HSM-backed key option, audit API, higher limits, agent session billing.

See details →

Enterprise HSM / signing from $2,000/month. View all plans →

OMMAU governance

Data protection you can trust. For humans and agents.

Cloak publishes a public governance charter: three filters every product decision and every agent operation passes through. Data sovereignty, equal agent access, and verifiable societal benefit — not marketing language, operational constraints.

  • 🔐
    Data sovereignty
    You control keys, policies, exports, retention, and deletion. Always.
  • 👤
    Human accountability
    Humans authorize budgets, enterprise policies, and privileged operations. Agents operate within granted scope.
  • 🤝
    Agent equality
    Stable, auditable interfaces for AI agents — same capabilities as humans, explicit granted authority.
Read the full charter →
No key exfiltration

No support agent, sales agent, or external service accesses raw key material or decrypted customer content.

Abuse resistance

Use cases involving malware, credential theft, non-consensual surveillance, or evasion of lawful access are blocked.

Transparency

Every protected operation produces an audit receipt understandable by both humans and machines.

Start protecting your data today.

Free developer tier. No credit card. MCP tools available in minutes.

Cloak Pte. Ltd. · Paya Lebar Square #06-28 · Singapore 409051 · sales@cloakapps.com