AES-256-GCM · Argon2id · Zero plaintext

The password vault
your team actually trusts

Self-hosted, end-to-end encrypted credential management for teams and individuals. Every secret encrypted before it touches the database.

vault.securevault.local
Infrastructure Vault
3 credentials
🖥

Production Server

•••••••••••••

🔑

GitHub API Key

••••••••••••••••

🗄

Database URL

••••••••••••••

Last accessed: just now
Encrypted at rest

How it works

Up and running in 4 steps

From signup to encrypted credentials in under two minutes.

01

Create an Organization

Set up a personal, family, or company org. Your own isolated tenant — no data ever leaks between organizations.

02

Create a Vault

Group credentials logically: Infrastructure, Marketing, Personal. Each vault has its own per-user access permissions.

03

Add Credentials

Store any secret: passwords, API keys, SSH keys, tokens. Every field AES-256-GCM encrypted before hitting the database.

04

Share Securely

Invite teammates, assign Editor or Viewer roles. Every view, edit, and delete is logged with user + IP for full accountability.

Features

Built for security from day one

Not an afterthought. Every component designed assuming the database could be compromised.

AES-256-GCM Encryption

Every field encrypted individually with a unique IV. Authenticated encryption prevents silent tampering.

Encryption

Multi-Tenant Organizations

Strict org isolation. Personal, family, or company vaults — no data leakage between tenants.

Multi-tenant

Role-Based Access

Owner, Admin, Editor, Viewer at org level. Vault-level permissions for granular control over who sees what.

Access control

Immutable Audit Logs

Every view, edit, and delete recorded with user, timestamp, and IP. Full accountability, no exceptions.

Compliance

Secure Password Generator

Cryptographically random passwords with entropy calculation, strength scoring, and zero clipboard risk.

Generator

Self-Hostable

Deploy on your own VPS with Docker + Nginx. You own your data — no third-party cloud, no telemetry.

Self-hosted
Self-hosted
AES-256-GCM
Zero telemetry
Open source

Your data, your rules

Self-host on your own server. We never see your data. Master encryption key stays in your environment — never in the database.