Security model

Scoped by default, logged by default, revocable in one click — and clear about what this product does not do.

Encryption at rest

Every credential is encrypted with AES-256-GCM using a 96-bit random IV before it is stored. Keys are scoped per project, so one compromise cannot become all of them.

Agents never hold keys

An agent asks the vault to perform an action against a pinned service. The vault performs it and returns only the result. No tool, endpoint or setting hands a credential to an agent.

Tamper-evident audit log

Every access — person or agent — is written to a hash-chained, append-only log. Revoking a connection stops it working immediately.

The limits

Unattended AI access requires a working key server-side, so we can technically read stored credentials. This is not a zero-knowledge product and we will never describe it as one.