Secure vault
The source stays on our side
Upload once. ArcticAuth obfuscates and encrypts it, then streams a single session copy over a websocket that is decrypted in memory. Nothing readable is written to disk on the client.


Hardware binding
Every key carries its own hardware and place bindings. A key that has been passed around stops at the gate instead of after the damage.
Per-session
Encrypted delivery
Hardware-bound
Key validation
Lua + C#
Client libraries
Live
Revocation control
One request, inspected
Delivery chain
Six gates, one request. The script only exists on the client after the last one clears.
Capabilities
Secure vault
Upload once. ArcticAuth obfuscates and encrypts it, then streams a single session copy over a websocket that is decrypted in memory. Nothing readable is written to disk on the client.
Keys and hardware
Issue keys through an ad checkpoint, a whitelist, or a direct grant. Set hardware binding and expiry per key, apply place policies during validation, and stop a shared key at the gate rather than after the fact.
Checkpoints
Route users through Linkvertise or your own provider, set the number of checkpoints, and switch between them from the dashboard. Keys already in the wild keep working.
Validation
Both talk to /api/validation/v1 over an encrypted envelope with a signed handshake, so a proxy in the middle sees a session token and nothing else.
Start protecting your delivery
Create a service, upload your script, and issue your first hardware-bound key from one dashboard.