Station70 FAQs
This article outlines Frequently Asked Questions.
- For the 3 levels of encryption (KMS, HSM, and Customer quorum m/n), what are the specific encryption algorithms used at each layer?
- Encrypted backup received from Fireblocks: RSA PKCS1 OAEP; Fireblocks-specified ciphersuite
- Cloud encryption via AWS KMS: AES-256-GCM; This is KMS’s symmetric encryption ciphersuite
- Operator YubiHSMs: Hybrid Public Key Encryption:. P256_HKDF-SHA256-AES-GCM-128. Uses the YubiHSMs Derive ECDH over P256 curve
- Customer Yubikeys (same encryption as YubiHSMs): Hybrid Public Key Encryption. P256_HKDF-SHA256-AES-GCM-128.
- What type of cryptography is Bunker using?
- Encrypted backup received from Fireblocks: RSA PKCS1 OAEP; Fireblocks-specified ciphersuite
- Cloud encryption via AWS KMS: AES-256-GCM; This is KMS’s symmetric encryption ciphersuite
- Operator YubiHSMs: Hybrid Public Key Encryption:. P256_HKDF-SHA256-AES-GCM-128. Uses the YubiHSMs Derive ECDH over P256 curve
- Customer Yubikeys (same encryption as YubiHSMs): Hybrid Public Key Encryption. P256_HKDF-SHA256-AES-GCM-128.
- How does Station70 secure backup packages to make sure no internal employees or outsiders can take my secrets?
- Using a 3/3 encryption where each shard of the encryption key is in a different environment including one of the shards being the customer quorum via hardware devices provides cryptographic security that unwanted parties cannot access backup packages.
- What is white glove onboarding?
- White glove onboarding provides a comprehensive assessment of an organization's existing disaster recovery operations and provides a tailored recommendation & implementation onto the Station70 platform.
- Whats included in the insurance?
- Station70 retains an insurance policy under its own name securing against negligence, misuse or unavailability of your backup keys. Clients are able to purchase additional coverage under their own name via our preferred insurance brokers.
- What is Failover Wallet ?
- In the event of a disaster, the Failover mechanism allows clients to hydrate new wallets or workspaces with their existing keys. Removing the need to expose private keys in a traditional recovery exercise.