PERMAFROST permafrost.live
Walrus × Sui · testnet
Data custody layer · Walrus × Sui

Storage that can prove itself.

Server-side encryption on Walrus. Ownership receipts on Sui. Uploads and reads that feel fast.

Talk to us → How it works Docs →
Ownership receipt Verified on Sui ↗
Receipt · ManifestNFT
0x36f7a7…ef742
Fingerprintsha256 97288b4a…e26558 Owner0x921924…e547 StoredWalrus aRgIzL…U0eiQ Lineage← prior version · linked
✓ register ✓ freeze ✓ verify
register
freeze → Walrus
verify on Sui
01 — Thesis

Not storage — the provable chain of custody storage enables. Verifiable by anyone. No account, no API, no trust in us.

02 — Capabilities
v1 v2 v3 ✓

On-chain provenance

A ManifestNFT per object: fingerprint, owner, version lineage. Resolves on Sui — independent of us.

your key
SSE-C

Encryption with your keys

SSE-S3, SSE-KMS, SSE-C — up to hold-your-own-key. Delete by destroying the key, with a certificate on Sui.

AWS CLI boto3 S3 API
gateway

S3-compatible gateway

SigV4 — AWS CLI, boto3, any S3 client. Edit freely, then freeze to Walrus to extend the lineage.

traced
to 1 licensee

Leak attribution

Per-licensee watermarking traces even a short snippet back to who leaked it. Records live on-chain.

03 — How it works
Proof · Sui
Data · Permafrost
Register
Fingerprint, encrypt, store, mint.
Access
Auth, license-check, stream, log.
Verify
Hash a file, look it up on Sui.
1 · Register
Fingerprint, encrypt, store, mint.
2 · Access
Auth, license-check, stream, log.
3 · Verify
Hash a file, look it up on Sui.
04 — Verify, without us

Hash the bytes. Resolve the receipt on any Sui fullnode. No Permafrost account required.

Open this receipt on Sui →
A real ManifestNFT on Sui testnet. Its on-chain root_hash is the file’s fingerprint — recompute and check it yourself.
verify · sui-fullnode
$ permafrost verify --hash 97288b4a…e26558
✓ found on Sui  ·  ManifestNFT
receipt     0x36f7a7…ef742
owner       0x921924…e547
root_hash  97288b4a…e26558 · == fingerprint
lineage    ← linked to a prior version
05 — The receipt survives
Permafrost · if it’s gone
receipt persists →
ManifestNFT · Sui

The receipt carries the fingerprint, ownership, and full version lineage. With the original bytes, anyone can recompute and prove provenance — without us.

06 — Who it’s for

Enterprises whose data carries rights — custody they can prove, not just storage they rent.

IP & media licensing Dataset owners Regulated archives

Built on Walrus — the premium publish-and-read layer for enterprise workloads.

07 — Questions

What actually goes on-chain?

Only the receipt: content fingerprint, owner, timestamps, version lineage. Never the content and never the keys — the bytes live encrypted on Walrus.

Do we need wallets or tokens?

No. You integrate through the S3 API you already use; the chain does its work underneath. The receipt still lands in an address your organization controls.

Who can read our data?

No one without an authenticated, license-checked request — and every read is logged. Keys can sit with us, in your KMS, or only with you. Destroy the key and the stored bytes have no reader left — and a certificate on Sui records that you did.

Are we locked in?

No. Your data comes back out through the same S3 API, and the receipt on Sui is yours either way — it doesn’t expire when a contract does.

Is this production-ready?

Permafrost runs on Walrus × Sui testnet today; mainnet is next. Early partners are shaping the licensing and audit surface now — a good time to talk.

Talk to us.

Walrus × Sui · testnet.

hello@permafrost.live →