Security model
Scoped by default, logged by default, revocable in one click — and clear about what this product does not do.
Encryption at rest
Every credential is encrypted with AES-256-GCM using a 96-bit random IV before it is stored. Keys are scoped per project, so one compromise cannot become all of them.
Agents never hold keys
An agent asks the vault to perform an action against a pinned service. The vault performs it and returns only the result. No tool, endpoint or setting hands a credential to an agent.
Tamper-evident audit log
Every access — person or agent — is written to a hash-chained, append-only log. Revoking a connection stops it working immediately.
The limits
Unattended AI access requires a working key server-side, so we can technically read stored credentials. This is not a zero-knowledge product and we will never describe it as one.