Protected by design. Explore the core
DOCUMENT PROTECTIONBUILT ON OPEN CRATE

CloseCrate.

Protected documents.
Built on an open core.

Close Crate is a document protection service built on Open Crate: encrypted files, verifiable authorship and policy-based access.

01 / THE PRODUCT

CLOSE CRATE / .cc

Share the document.
Define who can open it.

For teams sharing confidential documents with clients, partners and colleagues. Package the file with its author signature and access rules.

01 / ENCRYPT

Encryption travels with the file.

A .cc file carries encrypted document content. Authenticated chunks support streaming access and detect tampering as content is opened.

02 / VERIFY

Know who signed it.

Verify the document’s signed header, including its recipient key slots. Give recipients a verifiable author signature alongside the encrypted file.

03 / CONTROL

Set the terms of access.

Define access windows and permissions through policies and signed leases. The Close Crate viewer and access service apply those rules in supported workflows.

Rust

Built for speed. Designed for reliability.

Written in Rust for native performance, ownership checks and explicit error handling.

HYBRID POST-QUANTUM CRYPTOGRAPHY

Protect today.
Prepare for
what’s next.

Classical and post-quantum cryptography, working together to protect document keys.

01 / SOFTWARE HYBRID

X25519 + ML-KEM-768

A software hybrid built with X-Wing.

02 / HARDWARE HYBRID

P-256 + ML-KEM-768

A hardware-backed path on supported TPM devices.

How hybrid protection works

Hybrid protection is selected per key slot, not enabled by default for every file. Every sufficient path to a document key must meet the chosen protection profile. Author signatures are a separate mechanism.

About ML-KEM: NIST FIPS 203 ↗

Access restrictions depend on the client and deployment. Revocation cannot take back plaintext already extracted.

02 / THE OPEN CORE

RUST / FIVE LIBRARIES

Open Crate.

A Rust core for encrypted document containers.
Build your own application around it.

01Engine

The assembly. Package content and construct container headers.

02Policy

The decisions. Evaluate access rules against supplied facts.

03Crypto

The protection. Encryption, signatures and key derivation.

04Protocol

The messages. Activation, leases and revocation.

05Format

The container’s structure. Encode, parse and verify its contents.

Build with Open Crate.
Work with Close Crate.

FOR DEVELOPERS

Open Crate

Libraries you can build with.

Five Rust libraries for containers, cryptography, protocols, access rules and packaging. Build your own application around them.

Your application supplies file access, networking, time, randomness and enforcement.

Explore the Open Crate Rust core ↗

FOR DOCUMENT WORKFLOWS

Close Crate

A separate document protection service.

Document viewing, access management and supported desktop integrations, offered as a separate service.

Licensing Open Crate does not include the Close Crate service. Service availability and commercial terms will be announced separately.

03 / ON THE HORIZON

CLOSE CRATE / AI
IN DEVELOPMENT

AI features
coming soon.

We’re building AI features and a companion service for Close Crate.

A new part of Close Crate.

Details and availability will be announced here.

04 / TRUST & USE

OPEN TO SCRUTINY

Audit
the core.

Inspect the design.
Challenge the implementation.

Independent security review is next. Materials and submission details are coming soon.

INDEPENDENT AUDITS

Coming
soon.

Future audit reports and participating organizations will appear here.

No completed independent audit or participating organization is announced yet.

OPEN CRATE / LICENSING

Use it.Inspect it.Improve it.

Open Crate Community License 1.0
Source available

FREE USE / ENTERPRISE

Free for personal non-commercial use and companies with both less than $1M annual group revenue and fewer than 25 people. Commercial licensing is required when either threshold is reached.

Existing qualifying businesses receive a 90-day transition. Employees and individual contractors count across the corporate group. Full license text will accompany the repository release; Close Crate services are separate.

QUESTIONS / ANSWERED

FOR TEAMS & DEVELOPERS

Before you build.Before you share.

What is Close Crate?

Close Crate is a document protection service in development. It combines encrypted .cc containers, author signatures and policy-based access through its viewer and access service.

What is Open Crate?

Open Crate is the reusable Rust library core for container formatting, cryptography, protocol messages, policy evaluation and packaging. Developers can build their own applications around it; Close Crate is a separate service.

Does Open Crate support post-quantum cryptography?

Open Crate supports hybrid key encapsulation using ML-KEM-768 with X25519 (X-Wing) or P-256 (MLKEM768-P256). These protect document-key access; they do not make every signature or deployment post-quantum secure. The hybrid constructions follow pinned CFRG drafts. Use of ML-KEM is not a claim of FIPS certification.

Can revocation take back a document?

Revocation can restrict subsequent access through supported clients, subject to leases and offline windows. It cannot erase plaintext already extracted or guarantee protection on a compromised device.

How will Open Crate Enterprise licensing work?

The Community License is free for personal non-commercial use and businesses with both less than $1M in annual group revenue and fewer than 25 people. Reaching either threshold requires a commercial agreement, with a 90-day transition for existing qualifying users. Close Crate is a separate service; Open Crate is source-available under the Community License.

Are the AI features available?

AI features and a companion service are in development. Availability and details will be announced here.

05 / WHAT COMES NEXT

BUILT TO BE EXPLORED

Follow the project.
Look closer at the core.

Look inside

Close Crate & Open Crate