What Reindeer is
Reindeer is an encrypted storage and access API for large archives of JSON records. It runs as a managed service in Türkiye and gives every customer a dedicated cell. Every record is sealed with its own AES-256-GCM key, the ciphertext sits on a closed IPFS network and the keys sit in HSMs. When you delete a record, the keys that protected it are destroyed and you receive a signed erasure certificate that you can verify without trusting the server.
Reindeer provides storage and access only. Search, vector and AI work stay on your side.
Who it is for
Section titled “Who it is for”Organisations that keep large volumes of JSON data, have a duty to delete and need evidence that they did. The kind of data is up to you: customer and account records, order and transaction history, application and security logs, device and sensor readings, document metadata, content and social media archives. Ingest is source-agnostic; you name each record’s id, owner and timestamp with JSON pointers:
| Data | Id | Owner | Time |
|---|---|---|---|
| Customer record | /customer_id |
/account/id |
/updated_at, rfc3339 |
| Order | /order_id |
/buyer_id |
/placed_at, rfc3339 |
| Sensor reading | /reading_id |
/device/id |
/ts, unix |
| Social media post | /id_str |
/user/id_str |
/created_at, twitter |
Two kinds of users work with the system:
- Machines (your uploader and reader systems) connect over mutual TLS.
- People sign in with passkeys and hold one or more of seven roles: admin, approver, auditor, reader, deleter, operator, uploader.
What the design guarantees
Section titled “What the design guarantees”| Guarantee | How |
|---|---|
| Record-level encryption | Every record is sealed with its own key; that key touches no other record. |
| Closed network | Data stays on nodes that hold the swarm key; there is no path to the public network, a gateway or the DHT. |
| Provable deletion | Deleted records drop out of reads at once; their keys are destroyed and a signed certificate is issued. |
| Two-person rule | Sensitive actions wait for a second person’s passkey approval. |
| Verifiable audit | Key journals are hash chained and sealed with signed checkpoints. |
| Keys in HSMs | Epoch, recovery and signing keys are generated inside the HSMs and cannot be extracted. |
What the design does not guarantee
Section titled “What the design does not guarantee”- Reindeer claims no certification or external audit.
- Cryptographic erasure is a standards-based sanitisation technique; whether it suffices under a given regulation needs legal review.
- An upgrade path in which you keep the root key in your own HSM is part of the design, not yet a product feature.
Next steps
Section titled “Next steps”- Concepts: cell, batch, chunk, epoch and ledger.
- Quickstart: from the console to a first upload.
- The path of a record: every step from upload to destruction.