No custody as a starting point

Most data solutions promise to protect your information after taking custody of it. We build systems where we never take custody at all. Provii proves a fact without collecting the data behind it. downpipes backs up your cloud without the backups ever leaving your account. When the data paths into our hands do not exist, you do not have to trust that we will guard them.

We work in areas where regulation is moving fast and the usual approaches create the problems they claim to solve. Identity documents uploaded to third-party servers. Face scans stored in databases. Disaster-recovery vendors holding a copy of everything you own. Our systems prove or protect what matters without us holding it.

You cannot leak what you never had, and you cannot lose what only you can open. No-custody is not a feature. It is an architectural constraint.

What we are building

🪪

Provii

Privacy-preserving age verification using zero knowledge proofs. Confirm a visitor is old enough, or young enough, without collecting a name, a date of birth, or a face. Learn more →

🌧️

downpipes

No-custody backup and disaster recovery for the Cloudflare data layer. Runs in your own account, sealed under keys only you hold. We never see your data. Learn more →

🔧

Open building blocks

Beneath both products: open Rust crates for ZKP generation and verification, Pedersen commitments, and constant-time operations, plus post-quantum hybrid sealing for data at rest.

📐

Open specifications

Implementation-independent specifications, an age-verification protocol (Provii) and a frozen archive format (downpipes), so anyone can build a compatible verifier or reader.

How we work

📖

Open and auditable

Our code is published so you can check it. Provii is open source under a licence mix; downpipes is source-available with an MIT offline reader. Our ISMS documentation is public. Trust built on code, not promises.

🔗

Verifiable builds

SLSA-aligned provenance on every artefact, traceable to its exact source commit and build environment, Sigstore-signed. Signature-pinned, pull-only update channels.

🦀

Memory-safe foundations

Cryptographic cores in Rust, with zeroisation of sensitive values and constant-time comparisons enforced by static analysis. Type-safe TypeScript on the edge.

🌏

One management system

Age-verification mandates for Provii, data-protection and resilience obligations for downpipes, governed under one ISO 27001-aligned ISMS that we publish in full.

Founded by Tim O'Connor

Tim is a cybersecurity professional based in St Arnaud, a small town in regional Victoria, Australia. He currently works full-time as an Automation and Detection Engineering Lead, and founded Maelstrom AI to build the infrastructure he saw missing from the regulatory landscape: systems that meet compliance and resilience obligations without creating surveillance databases or single points of custody.

His background is in security operations, detection engineering, incident management, and information security leadership. Over the past fifteen years he has worked across managed security service providers, enterprise security teams, and government IT. He holds CISSP, CASP+, CySA+, PenTest+, Microsoft Cybersecurity Architect Expert, and Cloudflare security certifications. Outside of work, he volunteers with a Volunteer Bushfire Brigade.

Entity Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust
ABN 61 633 823 792
Jurisdiction Victoria, Australia
Address PO Box 169, St Arnaud VIC 3478

Work with us

If you are building in regulated industries and need privacy-preserving infrastructure, want to integrate age verification into your platform, or need no-custody backup for your Cloudflare estate, we would like to hear from you.