Encryption at rest
Sensitive vault fields are encrypted before they are written to storage. Encryption keys are managed through secure environment configuration, with a roadmap for per-organization keys on enterprise deployments.
Trust center
Credential and secret payloads are encrypted before persistence. Transport uses modern TLS between clients, browser extension and API services.
Sensitive vault fields are encrypted before they are written to storage. Encryption keys are managed through secure environment configuration, with a roadmap for per-organization keys on enterprise deployments.
All client and API traffic uses TLS. The browser extension, web app and mobile clients communicate only over HTTPS endpoints.
Vault list and search APIs return metadata only. Plaintext secrets are available through explicit reveal endpoints that are logged for audit.
BitLocker recovery keys, SSH keys, API tokens and certificates are stored with the same encryption boundaries as passwords—never in shared documents or chat exports.
Start a free trial or log in to review vaults, MFA and audit logs with your team.
Contact our security team for compliance mapping, DPAs and architecture reviews.