NewGoverned credential, secrets and access management—multi-tenant platform for businesses and MSPs.

Start Free

Trust center

Encryption at rest and in transit

Credential and secret payloads are encrypted before persistence. Transport uses modern TLS between clients, browser extension and API services.

Encryption at rest

Sensitive vault fields are encrypted before they are written to storage. Encryption keys are managed through secure environment configuration, with a roadmap for per-organization keys on enterprise deployments.

Encryption in transit

All client and API traffic uses TLS. The browser extension, web app and mobile clients communicate only over HTTPS endpoints.

No plaintext in list responses

Vault list and search APIs return metadata only. Plaintext secrets are available through explicit reveal endpoints that are logged for audit.

Key and recovery material

BitLocker recovery keys, SSH keys, API tokens and certificates are stored with the same encryption boundaries as passwords—never in shared documents or chat exports.

Evaluate passwhy in your own workspace

Start a free trial or log in to review vaults, MFA and audit logs with your team.

Security questionnaire or DPA?

Contact our security team for compliance mapping, DPAs and architecture reviews.