Your team's secrets, sealed before they leave the browser.
Secure Vault keeps your team's docs and .env files in one place. Everyday docs stay simple. Secrets are encrypted on your device with keys the server never sees.
- Argon2id
- X25519 sealed boxes
- AES-256-GCM
- Strict CSP + SRI
- Append-only audit log
production.env
Payments API · v14
- Database URLs
- API keys
- OAuth client secrets
- Signing keys
- SSH notes
- Webhook secrets
- Runbooks
- Onboarding guides
- Incident notes
- Architecture docs
STEP 1 / 6
You write a secret
It starts on your device. You type a .env file into a secure document. Right now it exists only in your browser's memory.
STEP 2 / 6
Your vault password unlocks your keys
Argon2id stretches your vault password into a key that unlocks your private key. The password itself never leaves this tab.
STEP 3 / 6
Encrypted before it leaves
The document is encrypted with the project's AES-256-GCM key, bound to this exact document and version so it can't be swapped or replayed.
STEP 4 / 6
The server stores only noise
Only ciphertext reaches the server. With full database access, or after a breach, it reads as random bytes.
STEP 5 / 6
Keys are sealed for each teammate
The project key is sealed to your teammate's public key (X25519). Only their private key can open it; the server just passes the envelope along.
STEP 6 / 6
Decrypted only on their device
Your teammate's browser opens the envelope and decrypts locally. Same secret on two devices, and never readable on the server.
Zero-knowledge storage
What you see. What the server stores.
Drag the handle. On the left is your .env file as it appears in your browser. On the right is everything the server, the database and its backups ever hold.
- Encrypted on your device. Before anything is sent, with keys that only exist in your browser's memory.
- Bound to its place. Every ciphertext is tied to its document, version and project, so it can't be swapped or replayed.
- Useless if stolen. A leaked database or backup contains ciphertext and sealed keys, not secrets.
AQAAAJw3sR0tX2VuY3J5cHRlZF9ibG9iX3Yx 9f2c41ab0e77d3c95a1f6be2840dd1c37a9e2f Kx8Qe+V2mT0oZ1pL4nR7sYb3/wJc6UdHfA9gNi c2VhbGVkIGJ5IHlvdXIgYnJvd3NlciBvbmx5Lg 3b7e1fa49d02c86e5f1a7b9c0d4e8f2a6b1c5d
# production.envDATABASE_URL=postgres://app:Xk29!pq@db/prodSTRIPE_SECRET_KEY=sk_live_51H8xQ2eZvKYlo2CAWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENGJWT_SIGNING_KEY=7f3a9c1e5b2d8f4a6c0e9b1d
Drag, or focus and use the arrow keys.
Everything in one place
A complete team vault, not just a password box.
Workspaces, roles, projects, docs and end-to-end encrypted secrets, with the admin tools a real team needs.
End-to-end encrypted secure documents
A purpose-built .env editor with masked values, one-click copy, import and export, plus encrypted Markdown and text. The server only ever stores ciphertext.
Roles with a real hierarchy
Owner, Admin, Manager and Member, plus custom roles ranked anywhere below you. Nobody can manage someone above them.
Automatic key sharing and rotation
Teammates get project keys from any unlocked key holder. Remove someone and the key rotates, re-encrypting every version.
Docs with full version history
Markdown and plain text with live preview. Every save is a version you can view, compare and restore.
Append-only audit log
Who did what, when, from where and with what result. Filter it, open any event for full details, export it to CSV. Nobody can edit it.
Workspaces and projects
Run several teams or clients from one account. Give each project its own members, and archive projects when they're done.
Notifications and alerts
Invitations, access granted, key changes and security alerts in-app and by email, such as repeated wrong vault passwords.
Fast to use
Command palette (Ctrl K), search, light and dark themes and a responsive layout that works on your phone.
Two kinds of documents
Simple where it can be. Sealed where it must be.
Choose per document. Normal documents stay convenient for everyday writing. Secure documents are encrypted end to end, so only your team can read them.
Security by design
The server is never trusted with your secrets.
Not by policy: by construction. The server enforces who may store or receive which encrypted blob, but it can't open any of them.
What the server stores
- Ciphertext of every secure document version
- Project keys sealed to each member's public key
- Your private key, encrypted by your vault password
- Public keys, used to share project keys
- Names, membership and the audit trail
What it never sees
- Your vault password
- Your private key or recovery key
- Any project key
- The contents of any secure document
- Values you copy, reveal or export
Argon2id
Turns your vault password into a key. Tuned to about one second per guess on your device.
X25519
Your personal keypair. Project keys are sealed to each member's public key.
AES-256-GCM
Encrypts every secure document, bound to its document, version and project.
CSP + SRI
Only our own scripts run, and each one is checked against a hash.
Self-hosted
Your server. Your keys. Your rules.
This site is a public demo for exploring. For real secrets, run the exact same Secure Vault on your own machine or server. It takes one command.
- Identical to the demo: same code, same features
- Your database, your backups, your network
- No third-party scripts, trackers or CDNs
- Postgres + Docker, nothing exotic
The demo is for trying things out. Anyone can sign up, and the data may be reset at any time. Never put real credentials in it.
$ git clone https://github.com/theabhipatel/vault.git$ cd vault$ ./scripts/dev.sh
FAQ
Questions, answered.
Can the people running the server read my secrets?
No. Secure documents are encrypted in your browser before they're sent, and the keys never leave your team's devices. Server operators see ciphertext, sealed keys and metadata such as document names.
What happens if I forget my vault password?
Use the recovery key you saved during setup to choose a new password. If you've lost both, you can reset your vault: teammates' browsers re-share project keys with you automatically, but projects only you could open become unreadable.
Is the demo the same as the self-hosted version?
Yes, it runs the same code. The demo is public and may be reset at any time, so use it to explore and self-host for anything real.
Do admins automatically get access to every secret?
Roles decide who is allowed to access secure documents, but the actual key has to be shared by a teammate who holds it. This happens automatically and in the background, without anyone ever handing a password around.
What does it cost?
Secure Vault is open source and free to self-host. You only pay for whatever server you run it on.
What if someone leaves the team?
Remove them and the project key rotates: a key holder's browser re-encrypts every version with a fresh key, so their old key opens nothing new.
More in the FAQ and troubleshooting guide.
Stop pasting secrets into chat.
Give your team one place for docs and credentials, where the secrets stay encrypted end to end.