VellumGuard has an open developer foundation and a private enterprise roadmap. The public SDK lets developers inspect, install, and test the core identity-scoped encryption model. The private enterprise layer is where customer-hosted deployment, file encryption, on-prem key custody, private transport integration, hardware entropy, native cryptographic modules, and regulated-environment workflows are developed with design partners.
The open layer is intentionally focused on the developer experience and the core programming model.
These are private/proprietary roadmap items and may be developed with design partners or licensed separately.
A direct comparison of what is available in the public open-developer layer versus what is developed privately with enterprise design partners.
| Capability | Public SDK / Open Developer Layer | Private Enterprise Layer |
|---|---|---|
| Basic SDK install | ✦ Yes | ✦ Yes |
| Text / JSON encrypt-decrypt | ✦ Yes | ✦ Yes |
| Public beta examples | ✦ Yes | ✦ Yes |
| File / package encryption | Roadmap note only | Private implementation |
| On-prem key custody | No | Planned / private |
| Customer-hosted deployment | No | Planned / private |
| Private transport / PAS integration | No | Private integration |
| TRNG / hardware entropy | No | Private integration |
| Native C++ cryptographic modules | No | Private implementation |
| Variable key-length workflows | No | Private roadmap / prototype |
| Edge node agent | No | Private implementation |
| Election / ballot workflows | No | Private prototype |
| Enterprise key rotation | No | Private roadmap |
| Audit / export / reporting | Basic events | Private enterprise reporting |
The public VellumGuard SDK is intended to make the developer experience transparent and easy to test. It includes the core TypeScript SDK, basic encrypt/decrypt examples, cohort messaging examples, and synthetic JSON payload examples.
Enterprise and customer-specific features are developed privately. This includes file and package encryption helpers, on-prem key custody, private transport and PAS integration, TRNG or hardware entropy support, native high-performance cryptographic components, edge node agents, election and ballot workflow prototypes, customer-hosted deployment, and enterprise administration features.
Some VellumGuard features involve proprietary partner technology, customer deployment architecture, key custody, private transport, hardware entropy, and performance-sensitive cryptographic implementation details. Those capabilities are developed privately with design partners and may be licensed separately.
No. The public SDK currently supports the hosted beta developer experience. On-prem deployment, customer-held key custody, private transport and PAS integration, TRNG-backed entropy, native C++ cryptographic acceleration, and variable key-length workflows are private enterprise roadmap items.
The current beta is limited to test, synthetic, or non-regulated data. VellumGuard is not currently SOC 2 certified, is not currently HIPAA compliant, and no BAA is currently available. Do not use VellumGuard for PHI, PCI card data, or regulated production data without a separate written data-handling agreement.
Contact beta@vellumguard.com to discuss your specific use case and whether the private enterprise layer may be appropriate for your requirements.
Enterprise features are developed with a small cohort of design partners. Apply to join the program.