rkv  holding & engineering — Wrocław KRS 0001173474 · owner of Encedo Limited

RKV sp. z o.o. · Wrocław, Poland

Don’t trust what
you can’t verify.
Us included.

RKV is the holding and engineering company behind the Encedo product line: cryptographic tools whose guarantees can be inspected rather than taken on faith. The same standard applies to the companies. RKV is on record in the Polish National Court Register, Encedo Limited at Companies House in London.

rkv.pl — basis of trust what survives checking
[claims]
Basis = our word for it ← asserted
Basis = registers + source ← checkable
 
[verify]
NIP = 8993025480
REGON = 541756532
Encedo = 09338846 · Companies House

Why RKV exists

Trust should be the result of checking, not a substitute for it.

RKV exists to build services and tools that people can rely on for the one reason that holds up: they looked. Read the code, test the hardware, open the register, and only then trust. Everything Encedo ships is built so that this order is possible, and nothing ships that would ask you to skip a step.

The prevailing standard is softer. A product says it encrypts, a service says it is secure, a policy says data is protected, and the customer is left holding a claim on a web page. Where that argument always stalls, at the question of who can reach the key, we put a piece of hardware in the customer’s hands that ends it: the key is generated inside the HEM and its API has no export call. The software around that hardware is open source, so the rest of the argument can be read rather than believed.

The second half of the purpose is quieter. The operator of a service should know almost nothing about the people who use it. Not because we promise to look away, but because the design never hands us the data: keys stay in hardware you hold, traffic ends at your own far end, and what we never receive we cannot leak, sell or be ordered to produce. Privacy that rests on the operator’s discretion is a policy. Ours is meant to be a property of the system, so that private means private again.

The working rule

A promise binds nobody. A design can.

Somebody once ran a very large company on don’t be evil. It was a good motto, and only a motto: a promise about future behaviour, revocable by whoever owns the promiser next. The rule we build by instead: do not trust a company, or a product, that cannot be validated. It decides what ships and what does not.

First · verifiable

What we claim, you can check

Source code you can read, under licences that let you keep it. Protocols that are public standards (WireGuard, OpenPGP, OIDC, PKCS#11), so a stock implementation on the other side is the test of every compatibility claim. Keys held in hardware in your own custody. And a company whose registered facts sit in state registers.

Second · independent

You can leave, and keep everything

Technological independence means the exit stays open: deployments you host yourself, formats that other software reads, far ends that stay ordinary, and no service of ours in the data path. If RKV disappeared tomorrow, your tunnels would still come up, your mail would still decrypt, and your data would still be yours. Dependence on a vendor’s continued goodwill is a liability we design out, starting with our own.

Third · evaluated

Checked once already, by people who were not us

The Encedo HEM went through a Common Criteria evaluation at EAL4+ and came out with a positive Evaluation Technical Report. The target of evaluation was the module together with its API: the whole surface a customer touches, not the cryptographic core on its own. It is a report, not a certificate, and the report is available to counterparties in due diligence.

What we build

One hardware root, standard protocols around it

The line is built on the Encedo HEM, a hardware encryption module. Keys are generated inside it and cannot leave; each product moves one more piece of trust from software assertion into hardware fact. Every product below carries its current status, finished or not.

hardware · the root of the line

Encedo HEM

A hardware encryption module in two versions, the EPA and the PPA, exposing one and the same API. Keys are generated inside and stay inside; the API simply has no export call. Every product below borrows its guarantees from that. The PPA is on sale; a small number of EPA units are available for evaluation.

Versions
EPA and PPA, one API between them
Keys
Generated in the module; the API has no export call
Evaluation
Common Criteria EAL4+, positive Evaluation Technical Report; module and API in scope
Interfaces
SDKs for JavaScript and Go; WireGuard, OpenPGP and OIDC through the products below; PKCS#11 in development
Availability
PPA for sale; EPA units for evaluation, on request: request a pilot

Shipping

live or released
released · open source

Encedo WG

A WireGuard-compatible client whose private key never leaves the module. The far end stays ordinary WireGuard and is not asked to know the difference.

live

Encedo OIDC

Single sign-on where the second factor is possession of the module, attested by the hardware itself rather than asserted by software on the host.

live · public builds

Onchato

A peer-to-peer messenger that keeps almost nothing on servers: end-to-end encrypted, minimal infrastructure, identities that can anchor to the module. For teams inside regulated organisations it is the channel that leaves nothing on a server to be subpoenaed or breached.

Built on the HEM

pilot · proof of concept · in development · research
pilot

Encedo OpenPGP

OpenPGP mail for the Carbonio suite with keys held in the module. Messages follow the RFCs, so any standard client, ours or not, can read them.

proof of concept · v1

HEM Mobile Authenticator

A mobile app that takes the place of the password when authorising to the module. Version 1, under its earlier name Encedo Manager, is a proof of concept and sits in the public repository as it stands. Version 2 is a rebuild rather than a patch, and is the release intended for Google Play and the App Store.

in development

Encedo Meet

Meetings on the open Jitsi stack, with end-to-end encrypted messaging in the room and the module anchoring identity.

in development

Encedo PKCS#11

The module behind the industry-standard PKCS#11 interface, so software you already run can use hardware-held keys unmodified.

research

Encedo Vault

Client-side encrypted storage over commodity clouds. The provider stores ciphertext and learns nothing else; changing provider is a copy, not a migration.

Around the module: three products live or released, one in pilot, one a proof of concept, and the rest in development or research; each product’s own page says the same. Every repository linked above is public, and the development happens where you can watch it, at github.com/encedo.

Who it is for, and why now

Key custody in hardware is becoming a requirement, not a preference.

The buyers are organisations that already have to prove where their keys live and who can use them. Between 2024 and 2027 a run of EU rules changes what they have to prove and to whom, and cryptographic hardware bought under the old regime comes up for replacement.

Who has to prove it

Trust services
Qualified trust service providers and public PKI operators under eIDAS, for whom key generation and custody in evaluated hardware is a condition of qualified status.
Financial entities
Banks, insurers, payment and crypto-asset firms and their ICT providers under DORA, and the essential and important entities under NIS2, whose key management is now a supervised control rather than an internal choice.
Critical infrastructure
Energy, water, transport and health operators, where the hardware root has to sit in the operator’s own custody and the far ends have to stay standard.

What changes, and when

Oct 2024
NIS2 transposition deadline: cryptography and key management become audited obligations for essential and important entities.
Jan 2025
DORA applies: ICT risk management and third-party oversight for the financial sector, cryptographic controls included.
Feb 2025
EUCC, the EU Common Criteria scheme, becomes operational; national certificates give way to EU ones, and products are re-evaluated under it.
2026
eIDAS 2.0: EU Digital Identity wallets due from every Member State by the end of the year, with qualified signatures and seals as the anchor.
Sep 2026 – Dec 2027
CRA: reporting duties from September 2026, full application from December 2027; products with digital elements, hardware included, need a conformity assessment to stay on the market.

The regulations are linked at source. Whether the HEM meets a given buyer’s requirement is settled by the evaluation report and the buyer’s own assessor.

Structure

Ownership is not our word for it. It is a record in two registers.

RKV sp. z o.o. of Wrocław owns Encedo Limited, a UK company incorporated in 2014. The Encedo assets are being consolidated into RKV during 2026; the products and their obligations continue under RKV. Both companies file publicly, in Poland and in the United Kingdom.

The structure is deliberately simple: one owner of record, a registered address that answers post, and numbers that resolve in a registry search.

Founder

The founder is on the record too.

RKV was founded by Krzysztof Rutecki, who has led the Encedo line since 2014.

On the record · two registers

Founder, on the record since 2014

CEO of RKV (prezes zarządu in the National Court Register), and a director and CEO of Encedo Limited since the company’s first day, 3 December 2014; his identity is verified by Companies House. One name behind the line for over a decade, on file in Wrocław and in London.

Asserted · our word for it

The discipline comes from safety-critical work

Embedded systems since 2005, much of it functional-safety work for mining and automotive, where “it works” has to be argued to an assessor. At Encedo, the cryptographic engineering and the Common Criteria evaluation described above. He has served on the boards of five companies. Earlier, six years of research at Wrocław University of Science and Technology in signal processing for speech recognition.

Company information

The registered facts, and where to check them

Everything below is a matter of public record held by the Polish National Court Register. RKV is a young company, registered in May 2025, and cannot show a decade of history; the Encedo line it holds has filed in London since 2014.

Legal name
RKV spółka z ograniczoną odpowiedzialnością
Registered office
ul. gen. Stefana Grota-Roweckiego 10/12, 52-220 Wrocław, Poland
Registry court
Sąd Rejonowy dla Wrocławia-Fabrycznej we Wrocławiu, VI Wydział Gospodarczy Krajowego Rejestru Sądowego
KRS
0001173474 — verify in the register
NIP · REGON
8993025480 · 541756532
Registered
19 May 2025
Management board
Krzysztof Rutecki, CEO (prezes zarządu, sole member) — also director and CEO of Encedo Limited since 3 December 2014
e-Doręczenia
AE:PL-69125-65164-TCUCA-19 — the state electronic-delivery address
E-mail
office@rkv.pl
$ curl -s 'https://api-krs.ms.gov.pl/api/krs/OdpisAktualny/0001173474?rejestr=P&format=json'
 the current extract — from the register itself, not from us

The same numbers, straight from the Ministry of Justice API. If we ever disagree with the register, believe the register and tell us.

Contact

One address, read by the people who build this.

No forms and no ticket queue. Tell us what you run and where this would fit, and whether you want a module on your bench to find out. If a register or a repository answers your question better than we can, we will say so.