Live demoSelf-host it for real secrets

Your team's secrets, sealed before they leave the browser.

Secure Vault keeps your team's docs and .env files in one place. Everyday docs stay simple. Secrets are encrypted on your device with keys the server never sees.

  • Argon2id
  • X25519 sealed boxes
  • AES-256-GCM
  • Strict CSP + SRI
  • Append-only audit log
vault.your-company.com

production.env

Payments API · v14

End-to-end encrypted
DATABASE_URL••••••••••••
STRIPE_SECRET_KEY••••••••••••sk_live_51H8xQ2eZvKYlo2C9
JWT_SIGNING_KEY••••••••••••
SENTRY_DSN••••••••••••
Decrypted in this browser · auto-locks in 15 min
  • Database URLs
  • API keys
  • OAuth client secrets
  • Signing keys
  • SSH notes
  • Webhook secrets
  • Runbooks
  • Onboarding guides
  • Incident notes
  • Architecture docs
How end-to-end encryption works

STEP 1 / 6

You write a secret

It starts on your device. You type a .env file into a secure document. Right now it exists only in your browser's memory.

STEP 2 / 6

Your vault password unlocks your keys

Argon2id stretches your vault password into a key that unlocks your private key. The password itself never leaves this tab.

STEP 3 / 6

Encrypted before it leaves

The document is encrypted with the project's AES-256-GCM key, bound to this exact document and version so it can't be swapped or replayed.

STEP 4 / 6

The server stores only noise

Only ciphertext reaches the server. With full database access, or after a breach, it reads as random bytes.

STEP 5 / 6

Keys are sealed for each teammate

The project key is sealed to your teammate's public key (X25519). Only their private key can open it; the server just passes the envelope along.

STEP 6 / 6

Decrypted only on their device

Your teammate's browser opens the envelope and decrypts locally. Same secret on two devices, and never readable on the server.

Your browserplaintext lives here
1DB_URL=postgres://u:pw@db/prod
2STRIPE_KEY=sk_live_51H8xQ2eZvK
3JWT_SECRET=7f3a9c1e5b2d8f4a6c
Argon2idAES-256
9f2c…
ServerPostgres
prod.env····················
key → Priyasealed·x25519
The server can't read any of this
sealed key
Priya's browserteammate
1DB_URL=postgres://u:pw@db/prod
2STRIPE_KEY=sk_live_51H8xQ2eZvK
3JWT_SECRET=7f3a9c1e5b2d8f4a6c
Waiting for access…
Opened with her private key Decrypted locally

Zero-knowledge storage

What you see. What the server stores.

Drag the handle. On the left is your .env file as it appears in your browser. On the right is everything the server, the database and its backups ever hold.

  • Encrypted on your device. Before anything is sent, with keys that only exist in your browser's memory.
  • Bound to its place. Every ciphertext is tied to its document, version and project, so it can't be swapped or replayed.
  • Useless if stolen. A leaked database or backup contains ciphertext and sealed keys, not secrets.
Your browserServer
AQAAAJw3sR0tX2VuY3J5cHRlZF9ibG9iX3Yx
9f2c41ab0e77d3c95a1f6be2840dd1c37a9e2f
Kx8Qe+V2mT0oZ1pL4nR7sYb3/wJc6UdHfA9gNi
c2VhbGVkIGJ5IHlvdXIgYnJvd3NlciBvbmx5Lg
3b7e1fa49d02c86e5f1a7b9c0d4e8f2a6b1c5d
# production.envDATABASE_URL=postgres://app:Xk29!pq@db/prodSTRIPE_SECRET_KEY=sk_live_51H8xQ2eZvKYlo2CAWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENGJWT_SIGNING_KEY=7f3a9c1e5b2d8f4a6c0e9b1d

Drag, or focus and use the arrow keys.

Everything in one place

A complete team vault, not just a password box.

Workspaces, roles, projects, docs and end-to-end encrypted secrets, with the admin tools a real team needs.

End-to-end encrypted secure documents

A purpose-built .env editor with masked values, one-click copy, import and export, plus encrypted Markdown and text. The server only ever stores ciphertext.

STRIPE_SECRET_KEY••••••
DATABASE_URL••••••
Copied. The clipboard clears itself in 30 seconds.

Roles with a real hierarchy

Owner, Admin, Manager and Member, plus custom roles ranked anywhere below you. Nobody can manage someone above them.

Owner1000
Admin900
Manager500
Member100

Automatic key sharing and rotation

Teammates get project keys from any unlocked key holder. Remove someone and the key rotates, re-encrypting every version.

v3
v4
re-encrypted

Docs with full version history

Markdown and plain text with live preview. Every save is a version you can view, compare and restore.

v14 · edited by Priya · now
v13 · restored from v11
v12 · edited by Sam · 2d

Append-only audit log

Who did what, when, from where and with what result. Filter it, open any event for full details, export it to CSV. Nobody can edit it.

Decrypted prod.envsuccess
Wrong vault passwordfailure

Workspaces and projects

Run several teams or clients from one account. Give each project its own members, and archive projects when they're done.

Notifications and alerts

Invitations, access granted, key changes and security alerts in-app and by email, such as repeated wrong vault passwords.

Fast to use

Command palette (Ctrl K), search, light and dark themes and a responsive layout that works on your phone.

Two kinds of documents

Simple where it can be. Sealed where it must be.

Choose per document. Normal documents stay convenient for everyday writing. Secure documents are encrypted end to end, so only your team can read them.

Normal
Secure
Who can read the content
Anyone with access, and the server
Only people holding the project key
Encryption
In transit (TLS) and access control
End-to-end: AES-256-GCM in the browser
Readable by the server
Version history
Best for
Runbooks, guides, notes
Credentials, keys, .env files

Security by design

The server is never trusted with your secrets.

Not by policy: by construction. The server enforces who may store or receive which encrypted blob, but it can't open any of them.

What the server stores

  • Ciphertext of every secure document version
  • Project keys sealed to each member's public key
  • Your private key, encrypted by your vault password
  • Public keys, used to share project keys
  • Names, membership and the audit trail

What it never sees

  • Your vault password
  • Your private key or recovery key
  • Any project key
  • The contents of any secure document
  • Values you copy, reveal or export

Argon2id

Turns your vault password into a key. Tuned to about one second per guess on your device.

X25519

Your personal keypair. Project keys are sealed to each member's public key.

AES-256-GCM

Encrypts every secure document, bound to its document, version and project.

CSP + SRI

Only our own scripts run, and each one is checked against a hash.

Self-hosted

Your server. Your keys. Your rules.

This site is a public demo for exploring. For real secrets, run the exact same Secure Vault on your own machine or server. It takes one command.

  • Identical to the demo: same code, same features
  • Your database, your backups, your network
  • No third-party scripts, trackers or CDNs
  • Postgres + Docker, nothing exotic

The demo is for trying things out. Anyone can sign up, and the data may be reset at any time. Never put real credentials in it.

$ git clone https://github.com/theabhipatel/vault.git$ cd vault$ ./scripts/dev.sh
Needs Docker, uv and Node 20.19+. Open http://localhost:29180 when it's ready. Full guide

FAQ

Questions, answered.

Can the people running the server read my secrets?

No. Secure documents are encrypted in your browser before they're sent, and the keys never leave your team's devices. Server operators see ciphertext, sealed keys and metadata such as document names.

What happens if I forget my vault password?

Use the recovery key you saved during setup to choose a new password. If you've lost both, you can reset your vault: teammates' browsers re-share project keys with you automatically, but projects only you could open become unreadable.

Is the demo the same as the self-hosted version?

Yes, it runs the same code. The demo is public and may be reset at any time, so use it to explore and self-host for anything real.

Do admins automatically get access to every secret?

Roles decide who is allowed to access secure documents, but the actual key has to be shared by a teammate who holds it. This happens automatically and in the background, without anyone ever handing a password around.

What does it cost?

Secure Vault is open source and free to self-host. You only pay for whatever server you run it on.

What if someone leaves the team?

Remove them and the project key rotates: a key holder's browser re-encrypts every version with a fresh key, so their old key opens nothing new.

More in the FAQ and troubleshooting guide.

Stop pasting secrets into chat.

Give your team one place for docs and credentials, where the secrets stay encrypted end to end.