Nebula Vault is a private file-collaboration and remote-access system, installed on customer-approved infrastructure you control. Every customer gets a separate deployment: its own database, its own storage, and deployment-specific access and recovery controls where enabled.
Contracts, financial records, and case files still leave the building over email threads and consumer cloud links because the alternative often means handing that data to a shared platform. Nebula Vault offers a different model by running as a dedicated environment on infrastructure your organization approves.
Every invitation, password reset, and VPN instruction is built from one canonical configured domain — never from whatever hostname an incoming request happens to carry.
If the malware scanner, its socket, or its binary is unavailable, the upload is refused with a temporary-service error. Nothing slips through while inspection is down.
Backup tooling is designed for a repository outside the application server and records success only after integrity checks pass. The final topology and restore drill are accepted per deployment.
Many collaboration services separate customers inside shared application infrastructure. Nebula Vault takes a different approach: a complete, separate stack per customer on an approved physical server, virtual machine, or dedicated cloud instance.
Folders, granular share permissions, starring, trash recovery, and search across everything you store.
Soft-delete + restoreAccess-controlled spaces for exchanging files and messages with people outside your organization.
Invitation-based, revocableProduct-neutral WireGuard tooling for deployments where customer IT approves managed remote access.
Optional · deployment-specificEvery file is scanned before it is stored, and a scanner outage refuses the upload instead of skipping inspection.
ClamAV · fail-closedDeduplicated snapshot and restore tooling, designed for a repository on a separate physical system.
Restic · restore verificationTwo-factor authentication for administrators; sessions revoke automatically on role or password change.
TOTPSharing, administration, and VPN enrollment events are recorded as they happen and remain reviewable.
Reviewable eventsEach release ships as a checksummed, signed archive, and each install verifies an offline-issued licence.
Offline key · SHA-256Every engagement follows a defined sequence, from understanding how your organization works to validating the environment and handing it over with clear operating guidance.
The result is a deployment with a documented scope, clear responsibilities, and a practical path from evaluation to operational acceptance.
Nebula Vault provides the product and deployment controls. Your organization retains authority over where it runs, who can access it, and how its operational responsibilities are defined.
| Nebula Vault | Your organization | Shared outcome | |
|---|---|---|---|
| Infrastructure | A dedicated deployment environment for each customer | Selects or approves the physical, virtual, or dedicated cloud environment | A clear operational boundary around your organization |
| Data | Separate application database and private file storage | Defines ownership, access, retention, and internal policy | No shared customer datastore |
| Access | Roles, invitations, session controls, and optional private connectivity | Approves administrators, members, guests, and remote-access policy | Controlled collaboration across internal and external users |
| Recovery | Encrypted backup and isolated restore tooling | Provides or approves a separate backup destination and recovery requirements | A recovery process tested against the approved environment |
The final architecture, operating responsibilities, and service expectations are documented for each deployment.
Nebula Vault is currently available through selected early-access engagements. Scope and acceptance are defined for each deployment.
Start with a focused conversation about what your organization needs to exchange, who should have access, and where the system should run. We define a clear evaluation scope before any deployment begins.
Discuss your deployment lumivyn@gmail.com