SpaceComputer

Introduction

Key management, secret storage, and the path to trusted execution in orbit.

What is SpaceComputer?

SpaceComputer develops infrastructure for security-critical workloads, with a roadmap toward key custody and confidential computation on satellites in low Earth orbit. Physical isolation changes the threat model for hardware that holds private keys and executes sensitive code.

What's available today

Orbitport KMS is available as an experimental beta for key management and tenant-scoped JSON secret storage. Create keys, encrypt and decrypt data, sign messages, generate data keys, and rotate keys using the TypeScript SDK or JSON-RPC API.

The current KMS deployment and the orbital roadmap are distinct. See Key Management Beyond the Data Center for the progression from terrestrial infrastructure to orbital key custody.

How you access it: Orbitport

Orbitport is the API gateway. It validates bearer tokens, resolves the authenticated tenant, and routes KMS operations to the backend. The SDK provides sdk.kms for key operations and sdk.kms.keyStore for JSON secret storage.

Start with a token from the accounts portal for your target environment, then follow the KMS guide.

What's on the roadmap

SpaceTEE extends the physical-isolation model to general computation. Trusted execution environments protect code from the software stack; placing them in orbit adds a barrier to physical access. See SpaceTEE and Space Fabric for the design and its limitations.

Next steps

On this page