KOZOR Shield Logo KOZOR Enterprise B2B
Zero-Trust B2B Security Platform

Encrypted Communication &
Enterprise Cryptographic Governance

Kozor provides end-to-end encrypted team messaging, shared enterprise credential vaults, and one-way company broadcasts — without giving administrators access to private user content or decryption keys.

Core Security Invariant

Administrative authority over policies and membership does not grant decryption authority over private communications or credentials.

ADMIN AUTHORITY ≠ DECRYPTION AUTHORITY
KOZOR ZERO-TRUST ENCLAVE TELEMETRY — LIVE DEMO CONTEXT
● WebSocket Relay Connected
ORGANIZATION MODULES
🛡️ Enclave Control
🔒 Shared Vaults (X25519)
📢 Company Broadcast
📱 Device Inventory (<1s Revoke)
📜 SHA-256 Audit Stream
Active Hardware Enclaves & Key Wrappers VEK Epoch: 004
prod-api-credentials.vault (Shared Vault) X25519 Wrapped (105B)
Company Security Directive (Broadcast) Receipt Verified (100%)
Worker Device #mem_dev_409 WebSocket Authorized
SHA-256 Audit Event #aud_089 Hash Chained

Enterprise Problems We Solve

Kozor replaces fragmented SaaS tools with a unified, zero-knowledge security platform designed for strict organizational compliance.

🔐

Shared Enterprise Vaults

Eliminates credential leaks across team Slack channels or email. Securely share IT infrastructure passwords, API keys, and financial credentials with Ephemeral-Static X25519 key wrapping and automated Epoch re-keying when an employee leaves.

NORMATIVE SPEC: AEGIS-BIZ-VLT-001
📢

Company Broadcast & Document Delivery

Guarantees delivery of critical executive announcements, emergency security alerts, and employment contracts. Features one-way encrypted delivery with mandatory cryptographic read receipts and targeted recipient scoping.

NORMATIVE SPEC: AEGIS-BIZ-BC-001
💬

End-to-End Encrypted Communication

Protects corporate IP from server surveillance and cloud provider subpoenas. All team channels and 1-on-1 direct messages are end-to-end encrypted with zero server access to plaintext or private keys.

NORMATIVE SPEC: 02_E2EE_PROTOCOL
📱

Instant Zero-Trust Device Revocation

Prevents data leaks from stolen, lost, or compromised devices. Admins can trigger instant WebSocket disconnection in under 1 second, invalidating relay session tokens and wiping enclave cache keys.

NORMATIVE SPEC: 07_SESSION_DEVICE
🔑

2-of-3 Threshold WebAuthn Recovery

Prevents administrative lockout without creating insecure master passwords or super-user backdoors. Requires 2 of 3 authorized WebAuthn hardware passkeys over a 72-hour governance timer.

NORMATIVE SPEC: AEGIS-B2B-REC-001
📜

Tamper-Evident Audit Stream

Simplifies GDPR, SOC 2, ISO 27001, and HIPAA compliance. All administrative events are stored as cryptographic SHA-256 hash chains, providing immutable audit proof without exposing plaintext secrets.

NORMATIVE SPEC: 06_LOGGING_TELEMETRY

Transparent Enterprise Pricing

Flexible cloud and self-hosted deployment models tailored for organizations of any scale.

Kozor Cloud Starter

Free tier for small teams starting zero-trust adoption.

€0
Up to 10 active members
  • End-to-End Encrypted Team Channels
  • Shared Enterprise Vaults (Basic)
  • Company Broadcasts (All Members)
  • 90-Day Hash-Chained Audit Log

Kozor Self-Hosted / On-Prem

Full data sovereignty for regulated enterprises.

Custom
Dedicated infrastructure licensing
  • Air-Gapped & Offline RSA/Ed25519 License Validation
  • SIEM Integration (Splunk, Datadog Export)
  • SAML 2.0 / OIDC SSO & SCIM Provisioning
  • Dedicated SLA & Security Audit Support