arca Reservations Are Open
Reservations are open for arca, the personal data haven we are building for secrets you cannot afford to lose. A $99 USD partial prepayment per unit reserves a place in the limited first batch, currently targeting January 2027.
The tentative early-bird price is $669 USD for one arca, $539 USD each for two, and $499 USD each for three or more.
Founder’s Edition Hardware
arca comes from the same Coinkite shop that built COLDCARD, OPENDIME, TAPSIGNER, SATSCARD, and our other physical custody tools.
The Founder’s Edition hardware includes:
- a Rockchip RK3328 host running FreeBSD;
- an Arm Cortex-M33 security controller with TrustZone;
- ATECC608C and DS28C36BQ+T secure elements;
- a secure real-time clock, motion sensor, and active tamper-detect circuit;
- two USB power inputs, Power Over Ethernet, and an internal UPS;
- planned reproducible deterministic builds and decoy PIN paths.
These parts provide defence in depth. The FreeBSD host handles higher-level services. The Cortex-M33 security controller and two different secure elements put sensitive operations behind separate boundaries. The secure clock, motion sensor, tamper circuit, independent power inputs, PoE, and internal UPS add physical-state and availability controls. No single chip or feature is the whole security argument.
Passwords can be stored inside arca, but they are not its primary authentication model. Access uses physical 2FA tokens and one-time codes instead of a reusable password.
The problem is usually boring
The authenticator app was on the dead phone. The seed backup is in one building. The registrar login depends on one inbox. Production credentials exist in one employee’s notes. The emergency procedure is “ask Alice.”
These are small secrets with large consequences. They end up spread across screenshots, cloud drives, paper notes, laptops, chat history, password managers, and memory. Each tool may be useful. The recovery path is still fragile.
arca gives that root material a dedicated physical home.
It is intended for seed words, recovery codes, passwords, signing material, business keys, runbooks, inheritance notes, important encrypted files, and the instructions someone will need when the normal path is gone. For Bitcoin and crypto users, that can include wallet recovery material, exchange recovery codes, signing policies, and continuity instructions.
More than encrypted storage
One arca can work as a standalone physical safe for digital secrets. The larger design includes several services inside the same hardware custody boundary:
- an embedded password-manager server for personal and team credentials;
- an internal COLDCARD for transaction signing and policy-controlled workflows;
- HSM functions that let approved systems request signing or cryptographic operations without receiving the raw key;
- isolated spaces for family, work, company, partner, and hosted contexts;
- controlled access for people, services, and authorized agents.
This is pre-production hardware and software. The final interfaces and feature scope may change before release.
A password manager helps with daily logins. A NAS stores files. An HSM performs narrow key operations. arca overlaps with all three, but its main job is the recovery layer underneath them: the root credentials, policies, instructions, and encrypted copies that must still exist when a device, account, building, or person is unavailable.
One box is a safe. More than one is a Swarm.
One arca still means one device in one physical location. Two or more can mirror an isolated encrypted tenant across places you choose.
A second arca covers loss of the first device or building. A third location lets one box be offline for maintenance, travel, or an outage without leaving only one recovery copy. The locations can be a home, office, family property, company site, or another city or jurisdiction that fits your threat model.
You do not need to own every box in the Swarm. A trusted friend can host your isolated encrypted tenant on their arca without receiving access to its contents. You can host theirs in return. Think reciprocal safes, not a shared folder, login, or vault.
That is why the quantity pricing matters. Buying more than one is not about keeping a spare beside the first box. It is about removing one device, one building, and one local event as the only recovery path.
Business continuity without the shared-secret mess
Businesses accumulate secrets that quietly become infrastructure: production credentials, API keys, signing keys, vendor accounts, recovery codes, treasury material, and emergency runbooks.
arca is being designed so a business can separate those contexts by team, company, partner, or project. Selected secrets can be available under policy without copying them into chat, email, or every employee’s password manager. HSM functions can let a system request an approved operation without distributing the raw key.
Multiple arcas can keep encrypted recovery contexts in different offices or trusted locations. If a founder, administrator, finance lead, or other key person leaves or becomes unavailable, the company should have a documented path back that does not depend on reconstructing one person’s private ritual.
Inheritance and the dead-man switch
Families have the same continuity problem under worse conditions. A survivor should not have to reverse-engineer the owner’s digital life while dealing with an emergency.
arca is being built so selected secrets, documents, and instructions can have a controlled recovery path for chosen people. A planned dead-man switch can make selected material recoverable after defined inactivity or release conditions.
The useful version is not “miss one check-in and dump the whole vault.” Different people may need different instructions. A business context should remain separate from a family context. Sensitive releases need authentication, limits, and records.
The policy and release mechanics are still in development. arca will not determine whether someone has died, and it does not replace legal estate planning.
Reservation details
| Quantity | Tentative price | Due today |
|---|---|---|
| 1 | $669 USD | $99 USD |
| 2 | $539 USDper unit | $198 USD$99 per unit |
| 3 or more | $499 USDper unit · best unit price | $99 USDper unit |
The first batch is very limited and is currently targeting January 2027. Pricing and timing remain tentative while we finish the product.
If your recovery plan still depends on one phone, one building, one cloud account, or one person remembering everything, reserve arca.
Learn more about the product, Swarm backups, Founder’s Edition hardware, and how it compares with adjacent tools at arcasafes.com.