Introduction

What Secure Vault is, who it is for, and how normal and end-to-end encrypted documents differ.

3 min read Edit this page

Secure Vault is a self-hosted team vault. Your team keeps notes, runbooks and secrets in one place, organised into workspaces and projects, and the most sensitive documents are end-to-end encrypted in the browser so the server can never read them.

What Secure Vault does

Secure Vault gives every team a workspace. Inside a workspace you create projects, and inside projects you keep documents. People join a workspace by invitation, and their role decides what they can see and do.

Documents come in two kinds:

  • Normal documents hold plain text or Markdown. Access control protects them, and the server can read them.
  • Secure documents hold plain text, Markdown or .env files. Your browser encrypts them before they leave your device. The server only ever stores ciphertext, sealed keys and public keys. It never sees your vault password, your private key, a project key or a plaintext secret.

You pick the kind when you create a document, and you can't change it later.

Who it's for

Secure Vault is for teams that want to keep shared knowledge and shared secrets together, on infrastructure they control:

  • engineering teams sharing .env files, API keys and credentials across environments;
  • operations teams keeping runbooks next to the passwords those runbooks need;
  • small companies that want one self-hosted place for internal docs, with an audit trail.

You run it yourself with Docker, PostgreSQL and any SMTP mail server. There is no third-party service in the loop.

Normal vs secure documents

Normal documentSecure document
FormatsMarkdown, plain text.env, Markdown, plain text
Protected byAccess control (roles and project membership)End-to-end encryption in the browser, plus access control
Can the server read the content?YesNo, it only stores ciphertext
Needs a vaultNoYes, you set up and unlock your vault to read or write
Who can open itAnyone whose role can view documents in that projectAnyone whose role can view secure documents in that project and who holds a copy of the project key
Version historyYesYes, every version is encrypted
Good forNotes, runbooks, onboarding guides, architecture docsAPI keys, credentials, .env files, anything you'd never paste into chat
If you forget your vault passwordNot affectedYou need your recovery key to get back in

Document and project names are never encrypted, for either kind. Don't put a secret in a name.

Try the demo or host your own

There are two ways to use Secure Vault.

The public demo lets you try the product in your browser without installing anything. Use it to click around, create a workspace and see how secure documents behave.

Self-hosting is how you use Secure Vault for real. The source code is at github.com/theabhipatel/vault. You can run it on your laptop in a few minutes with one script, then deploy it to your own server with Docker Compose when you're ready.

Public demoSelf-hosted
SetupNoneDocker, uv and Node.js for development; Docker for production
Your dataMay be deleted at any timeStays in your own PostgreSQL database
Real secretsNeverYes
EmailHandled by the demoYour own SMTP server or provider
Google sign-inDepends on the demoOptional, with your own OAuth client

Where to go next

Enjoying Secure Vault?

A star on GitHub helps other teams find it, and keeps the project going.

Star on GitHub

Search the docs

Find a page or a section