Guardian VaultPer user

The password, the runbook and the machine, in one place

Credentials, documentation and files under one permission model and one audit trail — and connected to the devices and tickets they belong to.

It is a thirty-second demo and it tends to be the moment the rest of this makes sense.

reveal — dc-01 domain admin
requested by: j.ortiz · from: 10.0.4.22 · step-up: 4 min ago
permission: use (not reveal) — injected into session, never shown
linked: ticket TKT-1842 · host dc-01 · client Acme
audit: who, when, from where, which permission allowed it
$ rotate password → vault updated as you go

Three tools most teams run separately

A knowledge base, a credential vault and a document store. Sharing one permission model means you grant access once, and one audit trail means you can answer what happened without three exports.

Knowledge base

Nested categories with per-article permissions. Full revision history, side-by-side diffs, one-click restore. Comments and mentions, so the discussion stays with the article. Sensitivity levels, with alerting on the ones that matter.

Credential vault

Passwords, keys, API tokens, database and Wi-Fi credentials. One-time-password codes generated for you. Sharing that can expire, or burn after first use. Break-glass access with a reason and a second approver.

Document storage

Encrypted at rest, with full version history. Scanned for malware on the way in. Searchable inside the documents, not just their titles. Review dates, so nothing quietly goes stale.

How it connects

Into terminal and desktop. Remote sessions open already authenticated, on Windows, macOS and Linux.

Into automation. Workflows and scripts resolve the secrets they need at run time, without them sitting in the script.

And back out again. Rotate a password from the same window you connected in, and the vault is updated as you go.

Nothing expires without warning

Certificates, domains, warranties and licences all get tracked with an owner and a renewal date. A daily sweep tells the right people before it becomes an incident — and it covers credentials overdue for rotation and documents overdue for review too.

TLS certificatesSoftware licencesWarrantiesCredential rotationDocument review

Permissions that fit the job

Read, use, reveal, share, edit or administer

Granted per folder or per item, and able to carry an expiry date.

Revealing is an event

Who, when, from where, and which permission allowed it. Administrator overrides are labelled as such.

Step-up before sensitive reveals

The more sensitive the item, the more recently you must have authenticated to see it.

Share outward, carefully

Give a named client contact access to a specific article or credential through the portal, with an expiry — or one that burns shortly after first view.

A private vault your administrators cannot open

Everyone gets personal space alongside the shared company vaults. Personal items are encrypted with a key derived for that person, and the owner-only rule is checked before any administrator override — including a super admin. An attempt to reach one is refused and recorded as its own event.

Ask us to connect to a server without showing you the password

Thirty seconds. Bring a sceptic.