Move data across clouds with cryptographic proof, not a signed SOW.
Server General builds data-transfer and database-encryption software for regulated, federal, and AI infrastructure. Our products deploy inside your cloud accounts — your IAM, your KMS, your perimeter. Data never touches us.
Encryption
- AES-256-GCM
- FIPS 140-2 Level 2
Signing
- ECDSA P-384 / SHA-256
Clouds Supported
- AWS
- GCP
- Azure
Product Portfolio · v3Live
Flagship · Data Transfer
Cross-cloud object transfer with signed chain-of-custody per object. Deploys across AWS, GCP, and Azure as a customer-owned mesh.
Private Connectivity
TG Connect
BGP-routed private interconnect across AWS, GCP, Azure, and Equinix. No public internet in the transfer path.
Throughput: Up to 50 Gb/s
Paths: Dedicated
Database Encryption
Armored SQL
File-level encryption for MySQL and PostgreSQL with no code changes. Compliance-ready for HIPAA, PCI DSS, and GDPR.
Deployment
- Customer-owned VPC
- Data plane: Never traverses SG
- Billing: MACC / CUD eligible
- Verified & listed: Google Cloud Ready
- Regulated & Sovereignty: GCP Marketplace
Transfer General is installed inside your cloud accounts — not routed through ours.
Transfer General is deployed as a mesh across AWS, GCP, and Azure. Data never traverses Server General infrastructure. Keys stay in your KMS. The control plane, audit log, and attestation record all live where your compliance scope already lives.
Key Features
- Three-cloud mesh deployment: AWS, GCP, and Azure in any two- or three-cloud combination.
- Object-layer encryption before transit: AES-256-GCM applied before data crosses any boundary.
- Signed attestation per object: Tamper-evident record including source hash, destination hash, and compliance mapping.
- Forensic-grade immutable audit log: Every event recorded in an append-only log.
Deployment Topology · Customer-owned
- YOUR AWS ACCOUNT: Source / staging, TG pipeline in-region, KMS: aws-kms
- YOUR GCP ACCOUNT: Landing / destination, TG pipeline in-region, KMS: gcp-kms
- YOUR AZURE ACCOUNT: Landing / destination, TG pipeline in-region, KMS: az-key-vault
Signing
- ECDSA P-384
- Clouds supported: 3 (AWS · GCP · Azure)
- Attestation: Tamper-evident
- Data touches SG: None
Three products, one deployment model — inside your perimeter.
Each product solves a different piece of the same problem: keeping regulated data under your own cryptographic and compliance control while it moves or lives in multi-cloud infrastructure.
TG Connect
High-speed private interconnect paths across AWS, GCP, Azure, and Equinix. BGP-routed, dedicated bandwidth with no public internet.
Throughput: Up to 50 Gb/s Pairing: With Transfer General
Armored SQL
File-level encryption for MySQL and PostgreSQL with zero application refactoring. Deploys as a drop-in layer between the database engine and the filesystem.
Engines: MySQL · PostgreSQL Compliance: HIPAA · PCI · GDPR
Who We Are
We build the cryptographic infrastructure your security team would have built — if they had the time and the cryptographers.
We do not
- Route your data.
- Hold your keys. Encryption keys are pulled on demand from your KMS — AWS KMS, Cloud KMS, or Azure Key Vault.
- Terminate your TLS. mTLS endpoints live in customer accounts.
Founded: 2015 Privately held: Baldwin, NY Deployments: Regulated only (Healthcare · federal · financial · AI)
How to Buy
Three procurement paths. All of them draw against existing cloud commitments. You do not need to stand up a new vendor relationship to run Transfer General, TG Connect, or Armored SQL.
- Google Cloud Marketplace: Transact against your Google Cloud commitment.
- Federal / SLED: Available through Carahsoft's public-sector contract vehicles.
- Direct: Annual or multi-year contracts direct with Server General. MSA & DPA templates available.