We build systems where the data stays yours

Maelstrom AI designs no-custody infrastructure for regulated environments. We prove facts without collecting them, and we protect data without ever taking custody of it. Two products, one principle: your data never becomes ours. Based in regional Victoria, Australia.

No-custody engineering for regulated industries

We design systems that hold as little of your data as possible, ideally none of it. Our work combines applied cryptography, privacy and data-protection regulation, production edge infrastructure, and open development.

🚫

No-custody architecture

The data paths that would put your personal information, or your backups, in our hands are architecturally absent. Not toggled off, not access-controlled. Missing by design.

🔐

Applied cryptography

Zero knowledge proofs that reveal a single bit, and post-quantum hybrid encryption that seals data under keys only you hold. Production-grade, memory-safe implementations.

📖

Open & source-available

Our code is published and auditable, and you can run it yourself. Cryptographic libraries, backend services, protocol specifications, and full backup engines. Trust built on code, not promises.

⚖️

Regulatory alignment

Built for the Online Safety Act (AU), GDPR (EU), Age Appropriate Design Code (UK), COPPA and CCPA (US). Our ISO 27001-aligned ISMS is published in full.

Two products, one principle

Both are built on the same conviction: the safest data to hold is the data you never had. One proves facts without collecting them. The other protects data without ever taking custody of it.

🪪

Provii

Privacy-preserving age verification using zero knowledge proofs. Websites and apps confirm a visitor meets an age threshold without ever receiving a name, a date of birth, a photo, or any identifying information. Works in both directions: "over 18" for restricted content, "under 13" for children's spaces.

🌧️

downpipes

No-custody backup and disaster recovery for the Cloudflare data layer. Scheduled, verified, post-quantum-encrypted backups of Workers KV, D1, R2, Secrets Store and your account configuration, running inside your own Cloudflare account and sealed under keys only you hold. We never see your data.

Technical capabilities

Applied Cryptography

Groth16 zero knowledge proofs on BLS12-381, Pedersen commitments, and post-quantum hybrid encryption for data at rest. Production-grade implementations in Rust with constant-time guarantees.

Edge Infrastructure

Cloudflare Workers serverless deployment. KV, Durable Objects, R2, rate limiting. No origin servers holding personal data, and backups that run entirely inside the customer's own account.

Supply Chain Security

SLSA-aligned build provenance. Sigstore-signed artefacts. Signature-pinned update channels. SHA-pinned CI dependencies. Automated licence compliance and vulnerability scanning.

Mobile & Systems Security

Hardware-backed keystores, biometric authentication, secure enclaves. Native iOS (Swift) and Android (Kotlin) with shared Rust cores via UniFFI. Memory-safe foundations throughout.

Regional Victoria. Global standards.

Based in St Arnaud, Victoria. We build under Australian privacy law, publish our ISMS documentation publicly, and develop in the open. Our code is open source and source-available, published and auditable.