RKV sp. z o.o. · Wrocław, Poland
RKV is the holding and engineering company behind the Encedo product line: cryptographic tools whose guarantees can be inspected rather than taken on faith. The same standard applies to the companies. RKV is on record in the Polish National Court Register, Encedo Limited at Companies House in London.
Why RKV exists
RKV exists to build services and tools that people can rely on for the one reason that holds up: they looked. Read the code, test the hardware, open the register, and only then trust. Everything Encedo ships is built so that this order is possible, and nothing ships that would ask you to skip a step.
The prevailing standard is softer. A product says it encrypts, a service says it is secure, a policy says data is protected, and the customer is left holding a claim on a web page. Where that argument always stalls, at the question of who can reach the key, we put a piece of hardware in the customer’s hands that ends it: the key is generated inside the HEM and its API has no export call. The software around that hardware is open source, so the rest of the argument can be read rather than believed.
The second half of the purpose is quieter. The operator of a service should know almost nothing about the people who use it. Not because we promise to look away, but because the design never hands us the data: keys stay in hardware you hold, traffic ends at your own far end, and what we never receive we cannot leak, sell or be ordered to produce. Privacy that rests on the operator’s discretion is a policy. Ours is meant to be a property of the system, so that private means private again.
The working rule
Somebody once ran a very large company on don’t be evil. It was a good motto, and only a motto: a promise about future behaviour, revocable by whoever owns the promiser next. The rule we build by instead: do not trust a company, or a product, that cannot be validated. It decides what ships and what does not.
Source code you can read, under licences that let you keep it. Protocols that are public standards (WireGuard, OpenPGP, OIDC, PKCS#11), so a stock implementation on the other side is the test of every compatibility claim. Keys held in hardware in your own custody. And a company whose registered facts sit in state registers.
Technological independence means the exit stays open: deployments you host yourself, formats that other software reads, far ends that stay ordinary, and no service of ours in the data path. If RKV disappeared tomorrow, your tunnels would still come up, your mail would still decrypt, and your data would still be yours. Dependence on a vendor’s continued goodwill is a liability we design out, starting with our own.
The Encedo HEM went through a Common Criteria evaluation at EAL4+ and came out with a positive Evaluation Technical Report. The target of evaluation was the module together with its API: the whole surface a customer touches, not the cryptographic core on its own. It is a report, not a certificate, and the report is available to counterparties in due diligence.
What we build
The line is built on the Encedo HEM, a hardware encryption module. Keys are generated inside it and cannot leave; each product moves one more piece of trust from software assertion into hardware fact. Every product below carries its current status, finished or not.
A hardware encryption module in two versions, the EPA and the PPA, exposing one and the same API. Keys are generated inside and stay inside; the API simply has no export call. Every product below borrows its guarantees from that. The PPA is on sale; a small number of EPA units are available for evaluation.
Shipping
live or releasedA WireGuard-compatible client whose private key never leaves the module. The far end stays ordinary WireGuard and is not asked to know the difference.
Single sign-on where the second factor is possession of the module, attested by the hardware itself rather than asserted by software on the host.
A peer-to-peer messenger that keeps almost nothing on servers: end-to-end encrypted, minimal infrastructure, identities that can anchor to the module. For teams inside regulated organisations it is the channel that leaves nothing on a server to be subpoenaed or breached.
Built on the HEM
pilot · proof of concept · in development · researchOpenPGP mail for the Carbonio suite with keys held in the module. Messages follow the RFCs, so any standard client, ours or not, can read them.
A mobile app that takes the place of the password when authorising to the module. Version 1, under its earlier name Encedo Manager, is a proof of concept and sits in the public repository as it stands. Version 2 is a rebuild rather than a patch, and is the release intended for Google Play and the App Store.
Meetings on the open Jitsi stack, with end-to-end encrypted messaging in the room and the module anchoring identity.
The module behind the industry-standard PKCS#11 interface, so software you already run can use hardware-held keys unmodified.
Client-side encrypted storage over commodity clouds. The provider stores ciphertext and learns nothing else; changing provider is a copy, not a migration.
Around the module: three products live or released, one in pilot, one a proof of concept, and the rest in development or research; each product’s own page says the same. Every repository linked above is public, and the development happens where you can watch it, at github.com/encedo.
Who it is for, and why now
The buyers are organisations that already have to prove where their keys live and who can use them. Between 2024 and 2027 a run of EU rules changes what they have to prove and to whom, and cryptographic hardware bought under the old regime comes up for replacement.
The regulations are linked at source. Whether the HEM meets a given buyer’s requirement is settled by the evaluation report and the buyer’s own assessor.
Structure
RKV sp. z o.o. of Wrocław owns Encedo Limited, a UK company incorporated in 2014. The Encedo assets are being consolidated into RKV during 2026; the products and their obligations continue under RKV. Both companies file publicly, in Poland and in the United Kingdom.
The structure is deliberately simple: one owner of record, a registered address that answers post, and numbers that resolve in a registry search.
Founder
RKV was founded by Krzysztof Rutecki, who has led the Encedo line since 2014.
CEO of RKV (prezes zarządu in the National Court Register), and a director and CEO of Encedo Limited since the company’s first day, 3 December 2014; his identity is verified by Companies House. One name behind the line for over a decade, on file in Wrocław and in London.
Embedded systems since 2005, much of it functional-safety work for mining and automotive, where “it works” has to be argued to an assessor. At Encedo, the cryptographic engineering and the Common Criteria evaluation described above. He has served on the boards of five companies. Earlier, six years of research at Wrocław University of Science and Technology in signal processing for speech recognition.
Company information
Everything below is a matter of public record held by the Polish National Court Register. RKV is a young company, registered in May 2025, and cannot show a decade of history; the Encedo line it holds has filed in London since 2014.
$ curl -s 'https://api-krs.ms.gov.pl/api/krs/OdpisAktualny/0001173474?rejestr=P&format=json' → the current extract — from the register itself, not from us
The same numbers, straight from the Ministry of Justice API. If we ever disagree with the register, believe the register and tell us.
Contact
No forms and no ticket queue. Tell us what you run and where this would fit, and whether you want a module on your bench to find out. If a register or a repository answers your question better than we can, we will say so.