MACE encrypts any file to the cloud, decides who can open it, redacts what shouldn't leak, and lets AI stop threats before they happen — and it shows you exactly how, in real time.
Every file that enters MACE runs a gauntlet — before it's ever stored. No jargon: play with the two live demos below.
Every file gets its own 256-bit key, locked inside AWS's hardware vault (KMS) and bound to your organization. Even we can't read it.
Access by who you are, your role, and how sensitive the file is — under hard tenant isolation no admin can override.
SSNs, cards, keys and tokens are stripped out before encryption, so they never travel.
Our safeguard scores every upload and share and blocks the risky ones before the damage — not after.
Spots the same party on both sides of a wall, or privileged data leaking into a public file — using one-way fingerprints that store no raw data. Unique to MACE.
Type a fake SSN, card, or key and hit Redact. Runs in your browser — nothing is sent anywhere.
Pick a person and a sensitivity — MACE decides, and tells you why.
Think of it as a smart firewall for your data and your fleet. Every event and every file flows through five stages. Hover any step.
Files, endpoints, connectors & logs stream in.
Deep content scan: secrets, malware signatures, anomalies.
Score across 7 domains + cross-matter identity — the MACE engine.
Allow · warn · block, with a reason — AI safeguard + policy.
Encrypt, quarantine or block — every action audit-sealed.
🔥 Like a firewall, but it inspects content and identity, not just ports — so it catches a leaked key or a conflict of interest a network firewall never could.
A fun, honest map of the flow — data moving from your world into MACE's brain and safely into the AWS cloud. Watch the packets travel.
MACE runs on AWS with defense in depth — so your data is protected by multiple independent layers, not one.
Two independent encryption layers: our per-file key wrap plus AWS server-side KMS encryption. Compromising one doesn't expose your data.
Public access blocked, TLS-only, KMS-only writes, versioning on. Least-privilege IAM — the app can touch only what it must.
Every key use and object access is logged immutably — provable to a regulator, searchable in Kibana.
Deploy per-region — US, GovCloud (FedRAMP), UAE, EU (GDPR), India (DPDP) — so data stays where the law requires.
Ships as containers; scales on EKS via Helm with autoscaling and rolling zero-downtime deploys.
Each tenant's keys are bound to their identity in KMS — one tenant's data physically cannot be decrypted in another's context.
Beyond files, MACE is a full correlation engine — turning noise from your existing tools into scored, explainable, compliance-ready action.
Native connectors for CrowdStrike, Tenable, Splunk, Axonius, MISP, plus the MACE agent — identities unify automatically.
Every event scored across seven domains before it becomes an alert — and every score explains itself.
22 frameworks across 5 jurisdictions; evidence auto-drafted with a cryptographic chain of custody.
Straight talk: the encryption, access control, redaction, AI safeguard and conflict engine are real and tested today. Before we hold live customer data we also complete an independent penetration test and security audit — trust should be earned, not just claimed.
Ask her in plain English. She reads your fleet, files and findings, never guesses, and warns you before a risky action.
Try asking: