Distributed Fragments Cryptography (DFC) by Akeyless is an innovative Key Management System designed to provide Root of Trust in a distributed non-trusted environment. It performs cryptographic operations using fragments of encryption keys stored across different regions and cloud providers. The actual encryption occurs on the customer side without combining the fragments, ensuring that there is no point in time or physical location where those fragments are connected, neither during creation nor usage. DFC allows for the complete encryption of customer data using encryption key fragments without ever combining them, eliminating the existence of a complete encryption key. This ensures that Akeyless and any other party besides the customer cannot decrypt the secrets, as Akeyless has zero knowledge of the encryption keys and secrets. DFC technology is based on standard cryptography and is FIPS 140-2 Certified by the US NIST. It adds security by constantly refreshing the mathematical values of the key fragments, which change dynamically without breaking their overall sum. This makes secrets almost impossible to hack, as an attacker would need to penetrate three separate cloud service providers and the customer’s environment to access different fragments simultaneously. DFC enables a lightweight, vaultless SaaS solution that is easy to deploy, maintain, and scale while maintaining the highest standard for security.