We've just launched. The site and the service are still being polished — we apologize in advance for any inaccuracies or rough edges. Spotted a mistake or something that doesn't work as expected? Tell us and we'll fix it quickly.

← All projects
EN
Beyond TAKT

escrow-box

Escrow box is an open-source prototype for placing a secret in a measured virtual machine and releasing it only under an agreed rule. The reference implementation covers source-code escrow. After sealing and verification, the VM can remain powered off until the release event needs to be checked.

  • TPM 2.0
  • UKI
  • Clevis
Status
Prototype: tested in local QEMU with swtpm; the repository documents a Shielded VM boot. Production use requires platform qualification and a verified handover. Wallet signing is a described application, not implemented in the source-escrow reference.
License
Apache 2.0.
Platforms
Linux x86-64; local QEMU/OVMF/swtpm harness and documented cloud experiments.

What it solves

A customer needs to check that an escrow deposit can rebuild the delivered binary while the vendor needs to keep the source private until the agreed event. The box separates verification from release.

Key features

  • The decryption key is sealed to the TPM and measurements of the boot image.
  • The source verifier rebuilds the delivered artifact and compares it byte for byte; only hashes and the result leave the box.
  • The reference release rule uses company-register status and a signed heartbeat, with a grace period for missing evidence.
  • Fixed SSH commands expose checks, status and release without an interactive shell.
  • After sealing and verification, the VM can be switched off and kept off until an event check is needed. Its disks can be backed up, removed from the host to free space, and restored when required. Keep the VM and its original TPM state: the TPM state is only a few kilobytes. The backup must include the image, encrypted deposit, sealed envelope and stored box state.

How it works

A unified kernel image contains the encrypted deposit, verification tools and release rule. Measured boot binds the key to that image. Protecting secrets in memory and TPM state depends on the selected platform.

provision → check → verify → status → unlock

Requirements

  • A Linux build host with the tools listed in the repository and a TPM-enabled VM.
  • For real escrow, a platform that prevents the receiving party from reading VM memory and TPM state, with agreed restart and recovery procedures.
  • An agreed release event, authenticated evidence and acceptance checks before depositing a real secret.
  • Preserve the same VM and TPM state; keep a complete disk backup and restore it to that VM under the agreed platform configuration.

This page summarises the repository’s README and documentation as of October 2026. The repository itself is the authoritative source.