CREDENTIAL VAULT

The right password, exactly where the work happens.

Not another vault in another tab. Credentials live inside the knowledge graph: on the configuration, next to the runbook, permission-scoped, audited, with OTP built in.

IN THE WORKFLOW

The silo is the problem.

A vault in a separate tab creates friction on every ticket. The useful credential is the one connected to the asset, client, and procedure that require it.

Keep credentials in context

Find the access detail next to the record and runbook that explain why it matters.

Apply the same boundaries

Respect role, client, and record-level access without a side channel.

Reduce app-switching

Reveal, copy, enter the code. Seconds, not app-switches.

ZERO-TRUST TO THE RECORD

Seeing a record doesn't mean seeing the secret.

View, reveal, and copy are three separate permissions:

VIEW recordREVEAL valueCOPY to clipboard
CRD.01

Encrypted with your own keys

AES-256 at rest, TLS 1.3 in transit, each tenant holding its own encryption keys. Masked by default.

CRD.02

Audited on every action

Reveals, copies, edits, and views land in an immutable trail retained at least one year, exportable to your SIEM.

CRD.03

Restricted by tag

A "Domain Registrar" tag locks an entire category away from tier-one techs in one move.

OTP BUILT IN

Reveal, copy, code, in.

Codes on the record

Time-based one-time codes generate right on the credential, live countdown included.

Seeds migrate from your legacy tool

MFA-protected logins keep working on day one. No second app, no phone hand-offs.

Safe near AI

Ask Lex surfaces a credential only to an authorized user; models never see raw values.

Zero-trust credentials, MSP-grade.

Permission-scoped, audited on every reveal, encrypted with per-tenant keys. The security posture your clients expect, built into the record.