Private infrastructure system

One vault.
One key.
One customer.

Nebula Vault is a private file-collaboration and remote-access system, installed on customer-approved infrastructure you control. Every customer gets a separate deployment: its own database, its own storage, and deployment-specific access and recovery controls where enabled.

0 shared databases 0 shared storage buckets 1 deployment per customer
Vault core · dedicated boundary Boundary 0%
Isolation
One deployment per customer. No shared tenant, ever.
Remote access
Optional WireGuard connectivity for approved deployments.
Uploads
Scanned before storage. Scanner down means upload refused.
Recovery
Encrypted backup tooling, designed for verified restore drills.
Why this exists

Sensitive files don't stop moving
just because there's a policy.

Contracts, financial records, and case files still leave the building over email threads and consumer cloud links because the alternative often means handing that data to a shared platform. Nebula Vault offers a different model by running as a dedicated environment on infrastructure your organization approves.

01 / Observations
Detail 01

No trust in the Host header.

Every invitation, password reset, and VPN instruction is built from one canonical configured domain — never from whatever hostname an incoming request happens to carry.

Detail 02

Fails closed, not open.

If the malware scanner, its socket, or its binary is unavailable, the upload is refused with a temporary-service error. Nothing slips through while inspection is down.

Detail 03

Backups that are proven.

Backup tooling is designed for a repository outside the application server and records success only after integrity checks pass. The final topology and restore drill are accepted per deployment.

Architecture

A system, not a platform.

Many collaboration services separate customers inside shared application infrastructure. Nebula Vault takes a different approach: a complete, separate stack per customer on an approved physical server, virtual machine, or dedicated cloud instance.

02 / Deployment model
Z+5HTTPS entry pointOne domain
Z+4VPN authorityWireGuard
Z+3Application nodeDedicated host
Z+2DatabaseCustomer-owned
Z+1File storageOutside web root
Z+0Backup repositoryOff-server
Deployment boundary explorer
Compare how customer environments are arranged under each deployment model.
Customer A db · files · vpn · backup
Customer B db · files · vpn · backup
Customer C db · files · vpn · backup
Customer D db · files · vpn · backup
Customer E db · files · vpn · backup
Customer F db · files · vpn · backup
Six customers · six dedicated environments · one deployment each
Select a customer to inspect its deployment boundary.
Modules

Eight parts. All of them have to hold.

03 / Capabilities
M01

Vault & sharing

Folders, granular share permissions, starring, trash recovery, and search across everything you store.

Soft-delete + restore
M02

Client rooms

Access-controlled spaces for exchanging files and messages with people outside your organization.

Invitation-based, revocable
M03

Private connectivity

Product-neutral WireGuard tooling for deployments where customer IT approves managed remote access.

Optional · deployment-specific
M04

Upload scanning

Every file is scanned before it is stored, and a scanner outage refuses the upload instead of skipping inspection.

ClamAV · fail-closed
M05

Encrypted backups

Deduplicated snapshot and restore tooling, designed for a repository on a separate physical system.

Restic · restore verification
M06

Two-factor & sessions

Two-factor authentication for administrators; sessions revoke automatically on role or password change.

TOTP
M07

Activity records

Sharing, administration, and VPN enrollment events are recorded as they happen and remain reviewable.

Reviewable events
M08

Signed releases

Each release ships as a checksummed, signed archive, and each install verifies an offline-issued licence.

Offline key · SHA-256
Deployment process

From requirements to a working
private environment.

Every engagement follows a defined sequence, from understanding how your organization works to validating the environment and handing it over with clear operating guidance.

04 / Delivery
nebula-vault · deployment journey structured
01Discoveryworkflows, users, infrastructure, and priorities understood
02Architecturedeployment boundary and access model agreed
03Configurationcustomer-specific private environment prepared
04Validationcore workflows and safeguards exercised
05Recoverybackup and restore procedure reviewed
06Handoveradministrator onboarding and operating guidance delivered

The result is a deployment with a documented scope, clear responsibilities, and a practical path from evaluation to operational acceptance.

Operating model

Private by design.
Adapted to your environment.

Nebula Vault provides the product and deployment controls. Your organization retains authority over where it runs, who can access it, and how its operational responsibilities are defined.

05 / Shared responsibilities
Nebula VaultYour organizationShared outcome
Infrastructure A dedicated deployment environment for each customer Selects or approves the physical, virtual, or dedicated cloud environment A clear operational boundary around your organization
Data Separate application database and private file storage Defines ownership, access, retention, and internal policy No shared customer datastore
Access Roles, invitations, session controls, and optional private connectivity Approves administrators, members, guests, and remote-access policy Controlled collaboration across internal and external users
Recovery Encrypted backup and isolated restore tooling Provides or approves a separate backup destination and recovery requirements A recovery process tested against the approved environment

The final architecture, operating responsibilities, and service expectations are documented for each deployment.

Operational safeguards

Security should be visible
in the way the system behaves.

06 / Current capabilities
Dedicated deployment environment for each customerCurrent build
Role-based access, two-factor authentication, and session controlsCurrent build
Upload scanning that refuses files when verification is unavailableCurrent build
Encrypted backup and isolated restore toolingCurrent build
Signed releases and deployment-specific licensingCurrent build
Administrative activity records and operational health visibilityCurrent build

Nebula Vault is currently available through selected early-access engagements. Scope and acceptance are defined for each deployment.

Selected early access

A private deployment shaped
around your organization.

  • Discovery session covering workflows, users, and infrastructure
  • A dedicated Nebula Vault evaluation environment
  • Customer-specific domain, deployment secrets, and administrator controls
  • Controlled sharing, client rooms, invitations, and role validation
  • Upload screening, health checks, and activity visibility
  • An encrypted backup and recovery demonstration aligned to the approved environment
  • Guided administrator onboarding, documentation, and acceptance review

Start with a focused conversation about what your organization needs to exchange, who should have access, and where the system should run. We define a clear evaluation scope before any deployment begins.

Discuss your deployment lumivyn@gmail.com