Station70 Bunker Trusted Recovery is a Wallet & Custody Security product by Station70. Pricing is commercial (price not published).
Bunker Trusted Recovery is a reference architecture from Station70 for recovering encrypted backups through a quorum based, multi party approval process. It splits a backup encryption key across three independent security domains: a customer share held by a quorum of approvers, an operations HSM share, and a cloud KMS share. Recovery requires all three domains and a customer defined M of N approval policy before any decryption occurs. Approving members authenticate and decrypt their portion of the customer share in a browser using a FIDO2 YubiKey, producing key material that is wrapped so only Station70's trusted execution environment (a Nitro Enclave) can use it. A single tenant CloudHSM in a separate AWS account decrypts the HSM share, and the TEE uses AWS KMS to decrypt the cloud share. Inside the enclave, the three shares are combined with Lagrange interpolation to reconstruct the backup encryption key, which is then used to decrypt the stored backup package layer by layer. The recovered backup is re encrypted to the customer's designated recovery public key before leaving the enclave, so it never exists in plaintext outside the TEE. The architecture is designed so Station70 cannot initiate or complete a recovery unilaterally, client browser compromise cannot leak usable key material due to transport wrapping, and if an approval policy becomes unsatisfiable due to lost devices or departed members, the backup is deleted and re ingested rather than the security requirement being weakened. Key components include a recovery policy engine for configuring approval thresholds, a browser based decryption site for approvers, a single tenant operations HSM, a Nitro Enclave TEE that performs reconstruction and decryption, and a ciphertext manager that serves encrypted material to the TEE at recovery time.</description> <parameter name="summary">Quorum based, TEE enforced recovery architecture for decrypting encrypted backups across 3 domains
Common questions about Station70 Bunker Trusted Recovery including features, pricing, alternatives, and user reviews.
Station70 Bunker Trusted Recovery is Bunker Trusted Recovery is a reference architecture from Station70 for recovering encrypted backups through a quorum based, multi party approval process. It splits a backup encryption key across three independent security domains: a customer share held by a quorum of approvers, an operations HSM share, and a cloud KMS share. Recovery requires all three domains and a customer defined M of N approval policy before any decryption occurs.
Approving members authenticate and decrypt their portion of the customer share in a browser using a FIDO2 YubiKey, producing key material that is wrapped so only Station70's trusted execution environment (a Nitro Enclave) can use it. A single tenant CloudHSM in a separate AWS account decrypts the HSM share, and the TEE uses AWS KMS to decrypt the cloud share. Inside the enclave, the three shares are combined with Lagrange interpolation to reconstruct the backup encryption key, which is then used to decrypt the stored backup package layer by layer. The recovered backup is re encrypted to the customer's designated recovery public key before leaving the enclave, so it never exists in plaintext outside the TEE.
The architecture is designed so Station70 cannot initiate or complete a recovery unilaterally, client browser compromise cannot leak usable key material due to transport wrapping, and if an approval policy becomes unsatisfiable due to lost devices or departed members, the backup is deleted and re ingested rather than the security requirement being weakened.
Key components include a recovery policy engine for configuring approval thresholds, a browser based decryption site for approvers, a single tenant operations HSM, a Nitro Enclave TEE that performs reconstruction and decryption, and a ciphertext manager that serves encrypted material to the TEE at recovery time.
Station70 Bunker Trusted Recovery is built for security teams handling Encryption, Key Management, MFA, AWS. Teams typically adopt Station70 Bunker Trusted Recovery when they need to web3 & blockchain security capabilities integrated into their existing stack. Explore similar tools at https://cybersectools.com/alternatives/station70-bunker-trusted-recovery
Station70 Bunker Trusted Recovery is a commercial Web3 & Blockchain Security solution. For detailed pricing information, visit https://www.station70.com/architectures/bunker-trusted-recovery/ or contact Station70 directly.
Popular alternatives to Station70 Bunker Trusted Recovery include:
Compare all Station70 Bunker Trusted Recovery alternatives at https://cybersectools.com/alternatives/station70-bunker-trusted-recovery
Station70 Bunker Trusted Recovery is for security teams and organizations that need Encryption, Key Management, MFA, AWS, AWS Security. It's particularly suitable for enterprises requiring robust, commercial-grade security capabilities. Other Web3 & Blockchain Security tools can be found at https://cybersectools.com/categories/web3-blockchain-security
Head-to-head feature, pricing, and rating breakdowns.
MPC-as-a-Service TSS platform for secure digital wallet key management.
MPC-based 2FA MetaMask Snap for distributed self-custodial wallets.
MPC network for distributed key management, signing, and wallet custody.