vaultterm --platform
One platform for secrets and access
A vault for every secret type, an audited broker for every session, and the team controls to run it safely — five parts that share one audit trail.
Credential vault
One vault for every kind of secret.
Store logins, SSH keys, API keys, environment files and secure notes in a vault organised by type — envelope-encrypted, never plaintext at rest, and built for how engineers actually work.
Learn moreTerminal, SSH & RDP broker
Every session brokered and audited.
Connect to any host — Linux over SSH or Windows over RDP — through an audited access broker. Access is injected just-in-time, decrypted in memory for the authorized session only, and written to a complete audit trail.
Learn moreTeams & JIT access
Share access without losing control.
Shared team vaults with role-based access and just-in-time elevation. Onboard and offboard people in one place, and keep an attributable record of who had access to what, when.
Learn moreBrowser extension
Your vault where you work.
Autofill logins and capture new credentials in Chrome and Firefox. The extension holds an encrypted copy of your vault on the device, so a fill is a local decrypt that works instantly and offline — sealed under a key your organization can withdraw, with every reveal still recorded.
Learn morePrivacy-first AI
Assistance that stays on your network.
AI help for the terminal and vault that defaults to a self-hosted model on your own LAN. Terminal output and secrets stay on your network unless your organisation opts a cloud model in — the default and that opt-in are what keep them there.
Learn morebroker status
It all runs through one audited broker
No standing credentials on laptops. The broker decrypts in memory for an authorized session, then everything is on the record — across every part of the platform.