Documentation
Everything about Secure Vault
Install it, invite your team, and keep secrets end-to-end encrypted. Clear guides for every feature, and an honest explanation of how the security works.
Start here
Getting started
What Secure Vault is and how to try it in minutes.
- IntroductionWhat Secure Vault is, who it is for, and how normal and end-to-end encrypted documents differ.
- Quick startCreate an account, a workspace, your vault and your first encrypted .env file in a few minutes.
- Core conceptsWorkspaces, roles, projects, documents, the vault and project keys, and how they fit together.
Self-hosting
Run Secure Vault on your own machine or server.
- Install and run locallyStart Secure Vault on Linux, macOS or Windows with a single command.
- Production deploymentDeploy with Docker Compose behind TLS, keep it updated and back it up.
- Deploy a demo on VercelRun a free public demo on Vercel and Neon with the same code, for people to try Secure Vault.
- Configuration referenceEvery setting for the API and the web app, with defaults.
- Email and Google sign-inSend email through any SMTP server and enable Sign in with Google.
Using Secure Vault
Workspaces, teams, roles, projects and documents.
- Accounts and sign-inSign up, verify your email, sign in, manage sessions and your profile.
- WorkspacesCreate, switch, configure, transfer and delete workspaces.
- Members and invitationsInvite teammates, accept invitations and manage who is in your workspace.
- Roles and permissionsBuilt-in and custom roles, every permission, and the hierarchy rules.
- ProjectsGroup documents and secrets into projects and choose who can access them.
- DocumentsWrite Markdown and text documents, view history, restore versions and search.
- Notifications and activityThe notification centre, email alerts and the dashboard activity feed.
The vault
End-to-end encryption: keys, secure documents and sharing.
- Set up your vaultChoose a vault password, create your keys and save your recovery key.
- Unlocking and auto-lockUnlock your vault, and how it locks itself to keep secrets safe.
- Secure documentsCreate end-to-end encrypted documents and manage .env files safely.
- Sharing secure accessHow project keys reach teammates, pending access and verifying fingerprints.
- Revocation and key rotationWhat happens when someone loses access, and how keys are rotated automatically.
- Password change, recovery and resetChange your vault password, use your recovery key, or reset your vault.
Security
How Secure Vault protects your data, and its limits.
- Security modelThe threat model: what the server stores, what it never sees, and how it is protected.
- CryptographyAlgorithms, the key hierarchy and how every ciphertext is bound to its place.
- Audit logEverything that is recorded, who can see it, filters, export and alerts.
- Known limitationsAn honest list of what end-to-end encryption in a browser can't protect against.
- FAQ and troubleshootingAnswers to common questions and fixes for common problems.
Enjoying Secure Vault?
A star on GitHub helps other teams find it, and keeps the project going.
Star on GitHubSearch the docs
Find a page or a section