Sovereign cloud

Your identity data. Your region. Your keys.

Healthcare data doesn’t get to leave the jurisdiction, and trust doesn’t get to depend on a vendor’s goodwill. OrthID runs as a managed, dedicated deployment in your region, encrypts with keys you hold, and keeps your data on your soil.

How it works

Sovereignty isn’t a setting. It’s a dedicated deployment.

A managed sovereign cell in your region, with keys you hold - control that survives a contract dispute, not a checkbox in someone else’s console.

A managed sovereign cell

OrthID runs as a dedicated, isolated deployment in your region on 3verest’s sovereign cloud. We provision, operate and upgrade it; you keep control of the boundary.

Region & residency

Pin identity data to a jurisdiction. One region runs today, with more on the way; data stays where the law - and your patients - require it to stay.

BYOK

Bring your own keys via Vault, KMS or HSM, so OrthID encrypts with keys it can use but never own. BYOK and HSM custody are available to design partners.

Tamper-evident audit

A hash-chained log makes every change provable and any tampering obvious - evidence, not just records.

Re-ID & keys stay home

Re-identification keys never leave sovereign storage. The data plane enforces the boundary; nothing exfiltrates by design.

Portable by standards

Open standards (OIDC, OAuth 2.0 token exchange) and clean data export. Your data and your keys leave with you, intact, on your terms.

Keys you hold

When you hold the keys, sovereignty isn’t a promise.

BYOK means OrthID can decrypt your data only while you let it. Rotate, suspend or revoke from your own Vault, KMS or HSM - and the lights go out on access without a support ticket. Re-identification keys never leave sovereign storage at all. BYOK and HSM custody are rolling out with design partners.

BYOK via Vault, KMS or HSM - your key store, your rotation policy
Hash-chained, tamper-evident audit - every change provable, any edit obvious
Region-pinned residency - data stays in the chosen jurisdiction
Re-ID keys never leave sovereign storage - no re-identification off your soil
Trust Center

Prove residency, keys and integrity at a glance.

Region, key custody and audit-chain health - visible to your security team and ready for an auditor.

app.orthid.io/sovereign/keys
Trust Center

Identity on your soil, under your keys.

A managed sovereign cell, region-pinned, with BYOK - your data stays in your region.