A system that
cannot delete.
Construction disputes are decided years after the work, on records nobody was curating at the time. XO Vault is the evidence layer being built for that moment: records sealed from elsewhere in BrieXO, retention with a reason attached, disposal suspended when a matter opens, and attested evidence bundles with a receipt for who took delivery.
A system that can delete has to prove it did not
That sentence is the whole argument. Most archives are trusted because of a policy. This one is being built so the capability is absent rather than restrained.
Nothing is deleted, because nothing can be
There is no deletion endpoint. The eligibility report is report-only, and the permission to authorise deletion exists solely as a reserved, inactive definition. In an adversarial conversation, absence of capability beats assurance of restraint.
It cannot quietly change
Immutability is enforced in the object layer rather than by convention. Bulk updates and deletes raise. Governance receipts, matters and legal holds each refuse deletion individually, and a released legal hold refuses status changes outright.
Retention has a reason attached
Policies are versioned and anchored to dated events rather than to ingest time, so "seven years after practical completion" is expressible directly. Retiring a policy does not delete it, because a record kept under a retired policy still needs its rationale readable.
What the design is aiming at
No deletion endpoint exists, and the authorisation permission is reserved and inactive.
Retention policies are versioned and anchored to dated events, not to the day a file arrived.
Evidence bundles are cryptographically attested and delivery is receipted.
Sealed, governed, attested
Records admitted from named sources, retention with a reason attached, and evidence bundles that carry a receipt.
An allowlist, not an upload box
XO Vault is not a document management system and not somewhere people drag files. It admits records from named sources so that what is inside it is answerable.
- Final XO Capture evidenceAdmitted as a source rather than uploaded by hand
- Issued XO Docs revisionsThe issued revision, not a copy somebody saved
- Allowlisted XO Ledger eventsSpecific events, from an allowlist
Governance the application enforces on itself
For a security-led buyer these are checkable rather than assertable, which is the distinction that usually matters.
- It refuses to start misdescribedSystem checks raise critical errors if the app is misregistered or reclassified as a released surface
- Unmapped methods are denied by constructionAny method without an explicit permission mapping requires a sentinel permission that exists nowhere except the line demanding it
- The event stream carries identifiers onlyBytes, storage keys, URLs, request bodies and credentials never enter the shared outbox or ledger mirror
Where XO Vault will sit
The evidence layer beneath the apps that produce authoritative records. In design.
XO Capture
Final evidence is admitted from Capture as an allowlisted source rather than uploaded.
XO Docs
Issued revisions are sealed as issued, not as a copy somebody kept.
XO Ledger
The Ledger records that events happened. Vault seals the allowlisted ones and governs how long they are kept.
Frequently asked questions
Is XO Vault available today?
Not yet. XO Vault is in development. If you are already thinking about how you will evidence a dispute years after the work, talk to us now and we will build with that case in view.
Can records be deleted?
There is no deletion endpoint. The eligibility report is report-only and the permission to authorise deletion exists as a reserved, inactive definition. That is the point: a system that can delete has to prove it did not.
Is this write-once storage?
Immutability is enforced at the object layer, and every export carries cryptographic attestation so it can be verified independently. That is a stronger guarantee than storage-layer write-once alone, because it travels with the evidence.
How does retention work?
Policies are versioned and anchored to dated events rather than to when a record arrived, so a rule like "seven years after practical completion" is expressible directly. Retiring a policy does not delete it.
Does it use AI?
No. There is no model, no adapter and no seam for one.
What still has to happen before you would sell this?
A real tenant with records sealed from all three sources, a rehearsed and recorded restore, an evidence bundle exported and receipted end to end, and a review by someone who would have to defend that bundle in a dispute.
Follow XO Vault as it is built
See the design, and the list of things that have to be true before we claim any of it publicly.