# IronCore Labs

**Canonical:** https://apis.io/providers/ironcore-labs/  
**Website:** https://ironcorelabs.com/  
**APIs profiled:** 5

IronCore Labs builds application-layer encryption tools that keep sensitive data private while it stays usable. Its products include SaaS Shield (tenant-controlled envelope encryption with customer-managed keys / BYOK for multi-tenant SaaS), Cloaked Search (a transparent encrypting proxy for Elasticsearch and OpenSearch), Cloaked AI (encryption of vector embeddings for AI/RAG workloads while preserving similarity search), the Data Control Platform (end-to-end encryption SDKs where the end user holds the key), and an S3 Proxy for per-tenant object encryption. Developers integrate through the unified IronCore Alloy SDK (Rust, Python, Java, Kotlin), the legacy Tenant Security Client (Node.js, Go, PHP), and the self-hosted Vendor API Bridge REST API for programmatic tenant and KMS configuration management.

## Kin Score — 54.0 / 100 (developing)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 54.0).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 56.2 |
| Governance | 11.5 |
| Operational Transparency | 55.3 |
| Developer Ergonomics | 69.0 |
| Commercial Clarity | 47.4 |

## Agent readiness — 42.1 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| MCP Server | derived |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Self-serve signup — onboarding: self-serve, pricing: unknown, trial: no (confidence: medium).

## APIs (5)

- **IronCore Labs Configuration Assignment API** — Assignments between KMS configurations and tenants
- **IronCore Labs KMS Configuration API** — KMS configurations from different providers (AWS, Azure, GCP, Thales)
- **IronCore Labs Tag API** — Label shared between service account configs and tenants. Controls where KMS configurations can be sent.
- **IronCore Labs Tenant API** — Vendor tenants managed by the Config Broker
- **IronCore Labs Tenant Secret API** — Tenant secrets created by the TSP and stored in the Config Broker

## MCP servers (1)

- **ironcore-labs-mcp.yml**

## Security (4)

- **Ironcore Labs Authentication** — apiKey · 1 scheme
- **Ironcore Labs Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Ironcore Labs Vulnerability Disclosure** — security.txt · contact published
- **Ironcore Labs Trust Center** — SOC 2

## Tags

Company, Encryption, Data Privacy, Security, Application-Layer Encryption, Key Management, Cryptography, AI, Vector Database, SaaS

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/ironcore-labs/). Scores are computed from the provider's own public artifacts under a published rubric.
