Sealed processing

Your records stay private.

Private by default. Provable on request. No one sees your records without your consent, and a signed receipt proves it whenever you ask.

Verify a receipt

About 3 minutes on a sample file. Your email and name open it. We never ask for your ACE login or bank details.

Sealed receiptOne for every Sealed run

Attested by AMD hardware

Launch measurement
Which code started
Platform flags
Memory alias check: complete
AMD signature
Chains to AMD's root

Stated by our code

Documents read
Each file's SHA-256 hash
Access paths
None: no SSH, no console, no staff review queue
What could leave
Files encrypted to you and your broker; claim totals to billing; this receipt
Working copy
Cryptographically erased, with the time

Receipt signature: signed inside the sealed machine

What every Sealed receipt records

Sealed or Standard

Who can read your documents in each mode?

Same checks, same licensed broker.

QuestionSealedReceipt includedStandard
Who can read your documentsOnly the people you approve, such as your broker. Exceptions go to you or your broker.Named NexQloud staff, only for exception review and support, with every access logged
The AI modelOpen-weight model, inside the sealed boundaryOutside AI may be used, on terms that bar training
Price⁠[1]20% of the first $500K recovered, falling above that18% of the first $500K recovered. Standard is 2 points less.
Nine more rows
QuestionSealedStandard
After the runWorking copy cryptographically erased; a signed receipt is keptKept for the engagement, then deleted on schedule
Where it runsAMD SEV-SNP confidential virtual machines (NexQloud Sealed)NexQloud cloud, plus an outside AI provider if one is used
TrainingYour documents are never used to train any model, and the model's weights hash is publishedYour documents are never used to train any model.
What leavesThe claim package and CSV go to your broker; claim totals go to billingSame
EncryptionEncrypted in your browser before upload, at rest, and in memory while the run is liveIn transit and at rest
What NexQloud can seeClaim totals, to billYour documents (named staff, only for exception review and support, every access logged), claim lines and claim totals
What your broker seesThe claim lines it files. A source document only if you release it, one at a timeThe claim lines it files and the documents behind them
What you can checkA receipt for every run, checkable against AMD's keysOur controls and your account's access log, with audit status on the trust center

How Sealed works

What keeps your documents out of our reach?

YouYour browser
  • Encrypts files before upload
  • Checks the AMD report before releasing your key

Host: outside the boundary

Sealed boundary

AMD SEV-SNP confidential virtual machine

  • 2The measured image, started from published code
  • 4No SSH, no console, debug off
  • The model and the calculation code
  • Your documents, readable only here, in memory AMD encrypts
  • 7The run's keys, destroyed at the end
AMD Secure ProcessorHolds the machine's memory key; signs the reportInside the trust base
  • Host operating system
  • Hypervisor
  • Our servers
  • Cloud storage: encrypted data only
  • Logs
  • NexQloud operators and staff
  • Physical access

5Only three things leave

  • Claim package and CSV
    6Your brokerEncrypted to them
  • Claim totals
    Billing
  • Receipt
    You
  • Inside the boundary: what you trust. AMD, our published code, and the verifier you choose.
  • Outside: everything else, including us.
Read the diagram as steps
  1. Diagram of a Sealed run in seven steps.
  2. Your browser encrypts each file.
  3. A sealed machine on AMD SEV-SNP hardware starts from published code, and your key is released only after its checks pass.
  4. Inside the solid Sealed boundary there is no login or console.
  5. Only files encrypted to you and your broker, claim totals and your receipt leave, and the working copy is erased at the end.
  6. Our servers, storage, logs, staff and the host sit outside the boundary.
The seven steps, in full
  1. Encrypted before it leaves you. Your browser encrypts each file before upload. Our load balancers, storage, logs and backups hold only encrypted data.
  2. A sealed machine starts from published code. Each run gets its own confidential virtual machine on AMD SEV-SNP hardware. AMD's chip gives it a memory key the host cannot read, and measures the code it starts with.
  3. Your key goes only to code that passes the checks. Before your key is released, your browser checks the machine's AMD report: a genuine AMD chip, patches at or above our published minimum, debugging off, and code that matches a release in our public log. If any check fails, the run does not start.
  4. No login, no console. The machine image has no SSH, no console and no remote shell. There is no staff review queue in Sealed mode.
  5. Only three things leave. Files encrypted to you and your broker, the claim totals our billing needs, and your receipt. Nothing else is allowed to leave the machine. No document content goes to logs, crash dumps or backups.
  6. Questions come to you, not to us. If the agent is unsure of a field, or a document is missing, you or your broker see the exception. Our staff do not.
  7. Erased at the end. When the package is done, the machine destroys the keys that decrypt its working copy. That is cryptographic erase. It then signs your receipt and shuts down, and AMD's chip discards the machine's memory key.
The four conditions behind the claim

"In Sealed mode, no one sees your documents without your consent" is true only while four conditions hold. We list them so you can hold us to them:

  1. There is no staff review path in Sealed mode.
  2. The machine image has no SSH or console, and debugging is off.
  3. NexQloud never holds a key that can open your documents.
  4. Encryption ends inside the sealed machine, not before it.

One more condition sits outside the software: our staff cannot physically reach the machines. AMD's protection does not cover physical attacks (limit 2).

Where your data is processed: our FAQ answer "Where is my data processed?"

The receipt

Can you check the receipt without trusting us?

Yes, for the parts the hardware proves. Open-source tools check it in a few commands.⁠[2]

What the receipt proves

  • AMD's chip signed the report, with a key that chains to AMD's root.⁠[3]
  • Which code the machine started with, and that debugging was off
  • No one changed a line after signing, including us

What it does not show

  • Any document content: only hashes, counts, versions and times
  • That our code told the truth
  • Where the machine was, or what your broker did next

Change one character and the check fails. The demo runs this test on sample data.

Each field and claim, and how to check it

Every Sealed run ends in a receipt. Some lines come from AMD's hardware. Others are statements by our code, signed inside the sealed machine. We mark which is which, because they deserve different levels of trust.

Attested by AMD hardware

These lines sit inside the AMD report. The chip signs the report with a key that chains to AMD's root certificate. If anyone changes a line after signing, including us, the signature check fails.

FieldWhat it tells youHow to check
Launch measurementExactly which code the sealed machine started with: firmware, kernel, start-up files and settingsCompare it with the release's entry in our public log, or recompute it (Verify, section 4)
DebugThe host could not use AMD's debug feature to read or change the machine's memoryRead the policy field in the AMD report
Platform patch levelsThe AMD firmware and microcode versions on the machineCompare with our minimum patch levels (Verify, section 5)
Platform flagsThe memory check AMD added after the 2024 BadRAM research has run on this machine⁠[4]Read the platform info field
BindingTies this receipt to this AMD report. It is a hash of the receipt's signing key and a random value your browser made for this runRecompute the hash (Verify, step 4)
AMD signatureAMD's chip signed the report. Its key chains to AMD's rootsnpguest or go-sev-guest (Verify, step 1)

Stated by our code

These lines are signed by a key our code creates inside the sealed machine for each run. The AMD report names that key and shows which code was running. AMD's hardware does not check what these lines say.

FieldWhat it tells youHow to check
Run IDWhich run this wasMatches the run in your account
ReleaseThe release the measurement belongs toIts entry in our public log
ModelWhich model read your documentsCompare it with the release's entry in our public log
Documents readHow many files went in, and exactly whichHash your own files and compare
OutputsThe exact files sent to your brokerHash the files you received
Access pathsWhat this release allowsA property of the published code; read the release notes
What could leaveEverything the machine was allowed to send outSame
Working copyThe keys to the working copy were destroyedA statement by our code; see limit 7
TimesWhen the run happenedFrom the server clock; not attested by hardware
Receipt signatureThe sealed machine signed every line aboveCheck it with the key bound in the AMD report (Verify, step 5)

Why trust a line our code states?

Because the AMD report shows which code was running when the receipt key was made, and that code is published. You, or a reviewer you hire, can read what it does. These lines are only as good as that code. That is why we publish every release and seek outside review.

What the receipt does not show

It holds no document content: only hashes, counts, versions and times. It does not show where the machine was, or what your broker did with the claim after receiving it.

Each Sealed claim, and how to check it

With those tools, you confirm that:

  • AMD signed the report, with keys that chain to AMD's root.
  • The platform's patches meet our published minimum.
  • Debugging was off.
  • The code matches a release in our public log.
  • The receipt was signed with the key that sealed machine named in its AMD report.
  • The files match the hashes in the receipt.
ClaimBacked byHow you checkLimits
In Sealed mode, no one sees your documents without your consentThe four conditions in section 3; the published machine imageReceipt: debug off, measurement matches the logged release. Release notes list the access pathsPhysical access (limit 2). You still trust AMD (limit 1)
Each run ends in a receipt anyone can check against AMD's keysThe AMD report inside the receipt, bound to the receipt keyThe verify page, with open-source tools such as snpguestShows which code ran, not that the code has no bugs (limit 5)
The working copy is erased at the endCryptographic erase in the published codeThe receipt's "Working copy" line; the release's codeA statement by our code, not by AMD. NIST's conditions apply (limit 7)
Your documents never train any modelThe model runs inside the sealed boundary; its weights hash is published; only encrypted files to you and your broker, claim totals and the receipt can leaveThe receipt's Model line names the weights that ranRests on the outbound block in the published code (limit 5)

If compelled

What could we hand over if a court ordered us to?

Only what we hold. In Sealed mode, that is very little.

WhatSealedStandard
Your documentsNo readable copy.Yes, until they are deleted on schedule
Extracted fields and claim linesNo readable copyYes, for the engagement
Claim totals and billing recordsYesYes
ReceiptsYes. They hold hashes, counts, versions and times, not contentNone issued
Account details: names, emails, company, broker choiceYesYes
LogsSystem logs with no document contentAccess logs: who opened which document, and when

If we receive a legal demand

We will tell you before we respond, unless the law forbids it.

Could we be made to change the code for one client?

A changed release has a new measurement. Your browser releases your key only to releases listed in our public log. So a release built for one client would sit in the log where everyone can see it.

Your records stay yours

This does not change your own records. You and your broker keep what CBP requires, for three years after the claim liquidates,⁠[5] and CBP can ask you for them.

Get started

Prove it on every claim.

Run the demo in Sealed mode. About three minutes.

  1. 01

    Choose Sealed.

    Pick Sealed mode when you upload your records.

    WhoYou

  2. 02

    The agent works inside the enclave.

    Your records are read inside AMD SEV-SNP hardware.

    WhoThe agent

  3. 03

    You get a signed receipt.

    The working copy is erased. Anyone you share the receipt with can verify it.

    WhoYou

Your email and name open the demo. We never ask for your ACE login or bank details.

Book a discovery call
Ready now? Start a claim

Honest limits

What does Sealed not protect against?

  1. You still trust AMD: its chips, firmware and signing keys. AMD ships fixes.⁠[6] In February 2025 it fixed a flaw that let an admin load bad microcode and remove a sealed machine's protection (CVE-2024-56161).⁠[7]
  2. Physical attacks are outside AMD's protection. Researchers broke SEV-SNP in 2025 with memory-bus devices costing under $50 to under $1,000.⁠[8]⁠[9] AMD calls these attacks out of scope. So who can physically reach our Sealed hosts matters.
  3. Side channels are outside AMD's protection too. Research continues (SNPeek and PowerHooK, 2026).⁠[10] We follow AMD's advice: constant-time cryptography and no secret-dependent branches in our code.
  4. A receipt is only as current as the platform's patches. We publish the minimum AMD patch levels we accept; our verifier rejects older platforms.
  5. Attestation proves which code ran, not that the code is free of bugs. That is why we publish every release and seek outside review.
  6. Outputs show what they must. Your broker sees the claim lines it files. CBP sees the filing. We see claim totals, to bill.
  7. "Erased" means cryptographic erase: the keys to the working copy are destroyed.

    NIST accepts this only if every key copy can be destroyed, encryption is at least 128-bit and the data was never stored unencrypted.

    It warns against it where keys were backed up or escrowed, unless their handling is well understood.⁠[11]

    Encrypted uploads, and any key share you hold, follow our retention table.

  8. Your records are still yours to keep. You and your broker keep the records CBP requires, for three years after the claim liquidates.⁠[5]
  9. Sealed is not a compliance certification. It is not CMMC, FedRAMP, or an ITAR or EAR authorization.⁠[12]

    If you hold CUI-marked files or drawings, keep them out of both modes.

    Leave export-controlled technical data (ITAR or EAR) out too, in either mode; drawback doesn't need it.

  10. Sealed protects secrecy, not uptime. The host can always stop a sealed machine. If a host fails, the run restarts elsewhere, so our 24-hour clock⁠* depends on the hosts staying up.
Every AMD bulletin we track

*24 hours from a complete package: entry summaries (CBP 7501), commercial invoices, packing lists, transport documents and export records for the period, plus the bill of materials and production records for manufacturing claims. We tell you the moment your package is complete, and the clock starts then. CBP rulings, waivers and approvals are separate from this clock.

Who it fits

Do you need Sealed?

Sealed fits records that must stay private: trade secrets (supplier prices, formulas or customer lists you protect), records for export-controlled goods, or a customer contract that requires confidential processing.

Standard is enough when your records hold nothing you would mind a named, logged NexQloud specialist seeing, or an outside AI provider processing. It costs 2 points less.

When Sealed fits, in full

Every importer's records show prices and customers. Invoices must show the seller, the buyer and the price of each item.⁠[13] Export filings name your customer.⁠[14] Sealed is worth it when those details are secrets, protected by you, by a contract or by law.

Sealed fits when your records hold any of these:

  • Trade secrets. Supplier prices, formulas or customer lists you protect as trade secrets or under a nondisclosure agreement.

  • A contract that requires it. A customer or contract that requires confidential processing.

  • Export-controlled goods or defense work (ITAR, EAR, DFARS). Sealed protects your export records, contracts and prices. Leave CUI-marked files, drawings and export-controlled technical data out of the file in either mode; drawback doesn't need them.

It also fits anyone who wants proof they can check. Brokers, CPA firms and refund firms whose clients send security questionnaires can tell them: your documents are processed where neither we nor our software vendor can read them.

What Standard protects

Standard protects your documents with our controls, not sealed hardware. An outside AI provider may process your documents, only on terms that bar training. Nothing trains on them. Only named NexQloud staff can open them, to fix an exception or answer a support request, and every access is logged. You can change modes for later uploads.

For brokers

In Sealed mode, you see the claim lines you file. If you need a source document to supervise a line, your client releases that document to you, one at a time, and the receipt records the release.

You choose the default mode for your clients' workspace. Clients can switch for later uploads.

Which mode fits your records

Price

What does Sealed cost?

The fee is charged on principal only, after CBP pays.⁠[1]

If CBP pays you

If CBP pays you $1,000,000, the fee is $175,000 with Sealed, an effective rate of 17.5%. With Standard it is $155,000, or 15.5%. You keep $825,000 or $845,000.

Sealed

Private by default. Provable on request.

$175,000

Effective rate
17.5%
You keep
$825,000
Standard: 2 points less

May use outside AI. Staff access logged.

$155,000

Effective rate
15.5%
You keep
$845,000
Show the math
Sealed
20% × 500,000 + 15% × 500,000 = $175,000 (17.5%)
Standard
18% × 500,000 + 13% × 500,000 = $155,000 (15.5%)
The full fee schedule

On $1,000,000 recovered in a lookback, the fee is $175,000 in Sealed (17.5% effective) and $155,000 in Standard (15.5% effective). Standard costs 2 points less on each percentage fee. The $750 minimum is the same. No retainer. No prefunding.

Worked examples (lookback)

Principal recoveredSealed feeStandard feeDifference
$250,000$50,000 (20.0%)$45,000 (18.0%)$5,000
$1,000,000$175,000 (17.5%)$155,000 (15.5%)$20,000
$5,000,000$685,000 (13.7%)$585,000 (11.7%)$100,000

The schedule (Standard is 2 points less on each percentage)

FeeSealedStandard
Lookback: first $500K recovered20%18%
Lookback: $500K to $2M15%13%
Lookback: above $2M12%10%
Ongoing program: up to $1M a year15%13%
Ongoing program: above $1M a year12%10%
Fixed annual option, from year 213% of the prior year11% of the prior year
In-house plan$15,000 a year (2,500 entries) or $37,500 (10,000)$12,000 or $30,000
Minimum per filed claim$750, never more than 25% of what the claim recoversSame

Filing by a NexQloud partner broker is included. So is the IEEPA sequencing check.

Your broker invoices you after CBP pays.

What the 2 points buy

No one sees your documents without your consent. Every Sealed run ends in a receipt anyone can check. The working copy is erased at the end. Every release is logged in public.

For brokers on the software model

A Sealed claim package is $1,250 instead of $1,000 (up to 1,000 matched lines), then $1.25 a line instead of $1.00. Workspace fees are the same in both modes.

See all fees and terms

Demo

Run the demo

Watch the agent turn a sample file into a claim folder. About 3 minutes.

We'll email you the link and add you to the waitlist. Unsubscribe anytime. We never ask for your ACE login or bank details.