Reservations are open for arca, the physical digital safe built for secrets you cannot afford to lose—our personal data haven. A $99 USD partial prepayment per unit reserves a place in the limited first batch, currently targeting January 2027.

The tentative early-bird price is $669 USD for one arca, $539 USD each for two, and $499 USD each for three or more.

Founder’s Edition Hardware

arca comes from the same Coinkite shop that built COLDCARD, OPENDIME, TAPSIGNER, SATSCARD, and our other physical custody tools.

The Founder’s Edition hardware includes:

  • a Rockchip RK3328 host running FreeBSD;
  • an Arm Cortex-M33 security controller with TrustZone;
  • ATECC608C and DS28C36BQ+T secure elements;
  • a secure real-time clock, motion sensor, and active tamper-detect circuit;
  • two USB power inputs, Power Over Ethernet, and an internal UPS;
  • planned reproducible deterministic builds and decoy PIN paths.
arca rear panel rendering showing status LEDs, two USB power inputs, USB data, SD card, and Power Over Ethernet
Founder's Edition rear panel.

These parts provide defence in depth. The FreeBSD host handles higher-level services. The Cortex-M33 security controller and two different secure elements put sensitive operations behind separate boundaries. The secure clock, motion sensor, tamper circuit, independent power inputs, PoE, and internal UPS add physical-state and availability controls. No single chip or feature is the whole security argument.

Passwords can be stored inside arca, but they are not its primary authentication model. Access uses physical 2FA tokens and one-time codes instead of a reusable password.

Recovery should not depend on one phone, one building, or one person

The authenticator app was on the dead phone. The seed backup is in one building. The registrar login depends on one inbox. Production credentials exist in one employee’s notes. The emergency procedure is “ask Alice.”

None of this requires a sophisticated attacker. Normal life is enough:

  • The phone is gone. You know the account password, but the authenticator, passkey recovery, or code needed to enroll a new phone lived on the old one.
  • Everything is in one building. The seed plate, emergency USB, printed codes, and recovery instructions are all “offline” in the same home or office. A fire, flood, evacuation, seizure, or long trip makes every copy unavailable at once.
  • One employee is the recovery plan. The registrar, cloud root account, signing process, and production credentials depend on a founder or administrator who left, is unreachable, or no longer remembers the full procedure.
  • The pieces exist, but the recovery path does not. The password is in a manager, one code is in email, another is on paper, and the final step lives in someone’s memory. Nobody has tested whether the pieces still work together.
  • Family must solve it under stress. They know important assets and accounts exist, but not which instructions are current, who should receive what, or how to start without exposing everything.

These are small secrets with large consequences. The usual fixes pull in opposite directions. Make more copies in screenshots, email, chat, and cloud drives, and sensitive material becomes easier to leak. Keep only one careful offline copy, and one dead device, inaccessible building, or unavailable person can lock everyone out.

A password manager is useful for daily logins. A NAS is useful for files. Paper and steel are useful static backups. A hardware wallet is useful for signing. Each solves part of the problem, but the recovery path can still depend on the same phone, inbox, cloud account, building, or person.

arca is built to turn that scavenger hunt into a custody plan. It gives critical secrets and their recovery context a dedicated physical home. The current design uses isolated tenants for family, business, partner, and hosted contexts. Policy controls and Swarm mirroring are in development so selected people can recover the right context and two or more arcas can keep encrypted copies in different trusted locations.

arca does not replace those tools. For everyday use, it protects daily backups, passwords, business access, files, and signing material on dedicated hardware. For continuity, it keeps the recovery layer underneath them: seed words, recovery codes, business keys, runbooks, inheritance notes, important encrypted files, and the instructions someone will need when the normal path is gone. A third path under development will give authorized agents narrow, policy-controlled access without handing them every secret. For Bitcoin and crypto users, that can include wallet recovery material, exchange recovery codes, signing policies, and continuity instructions.

More than encrypted storage

One arca can work as a standalone physical safe for digital secrets. The larger design includes several services inside the same hardware custody boundary:

  • a widely adopted password-manager server, likely Bitwarden and/or KeePassXC, for personal and team credentials;
  • an embedded COLDCARD signing emulator for remote multisig co-signing or a dedicated single-signature wallet;
  • CK Bunker-style HSM functions in development, so approved systems can request signing or cryptographic operations without receiving the raw key;
  • isolated spaces for family, work, company, partner, and hosted contexts;
  • controlled access for people, services, and authorized agents.

This is pre-production hardware and software. Some of this works in the alpha; some remains in design or prototyping. The final interfaces and feature scope may change before release.

A password manager helps with daily logins. A NAS stores files. An HSM performs narrow key operations. arca overlaps with all three, but it is broader than recovery alone: everyday backups and signing, personal and business continuity, and controlled access for authorized agents.

One arca is a safe. More than one is a Swarm.

One arca still means one device in one physical location. Two or more are designed to mirror an isolated encrypted tenant across places you choose.

A second arca covers loss of the first device or building. A third location lets one arca be offline for maintenance, travel, or an outage without leaving only one recovery copy. The locations can be a home, office, family property, company site, or another city or jurisdiction that fits your threat model.

You do not need to own every arca in the Swarm. The design lets a trusted friend host your isolated encrypted tenant on their arca without receiving access to its contents. You can host theirs in return. Think reciprocal safes, not a shared folder, login, or vault.

That is why the quantity pricing matters. Buying more than one is not about keeping a spare beside the first box. It is about removing one device, one building, and one local event as the only recovery path.

Business continuity without the shared-secret mess

Businesses accumulate secrets that quietly become infrastructure: production credentials, API keys, signing keys, vendor accounts, recovery codes, treasury material, and emergency runbooks.

arca is built to separate those contexts by team, company, partner, or project. Policy controls and CK Bunker-style HSM interfaces are in development so selected secrets can be available without copying them into chat, email, or every employee’s password manager. An approved system can request an operation without receiving the raw key.

Multiple arcas are designed to keep encrypted recovery contexts in different offices or trusted locations. If a founder, administrator, finance lead, or other key person leaves or becomes unavailable, the company should have a documented path back that does not depend on reconstructing one person’s private ritual.

Inheritance and the dead-man switch

Families have the same continuity problem under worse conditions. A survivor should not have to reverse-engineer the owner’s digital life while dealing with an emergency.

arca is built so selected secrets, documents, and instructions can have a controlled recovery path for chosen people. A planned dead-man switch can make selected material recoverable after defined inactivity or release conditions.

The useful version is not “miss one check-in and dump the whole vault.” Different people may need different instructions. A business context should remain separate from a family context. Sensitive releases need authentication, limits, and records.

The policy and release mechanics are still in development. arca will not determine whether someone has died, and it does not replace legal estate planning.

Reservation details

arca tentative pricing and reservation prepayments
Quantity Tentative price Due today
1 $669 USD $99 USD
2 $539 USDper unit $198 USD$99 per unit
3 or more $499 USDper unit · best unit price $99 USDper unit

The first batch is very limited and is currently targeting January 2027. Pricing and timing remain tentative while we finish the product.

If your recovery plan still depends on one phone, one building, one cloud account, or one person remembering everything, reserve arca.

Learn more about the product, Swarm backups, Founder’s Edition hardware, and how it compares with adjacent tools at arcasafes.com.