Product
Password and secrets management, from storage to the moment of use
One console on your own server covers vault records, the paired browser extension, selected-record sharing, Discovery, audit history, recovery, and optional Active Directory metadata sync.
Passwords, API keys, notes, certificates, and files
A record stays masked until an authorized user reveals or copies its value. The browser encrypts the secret before the server stores it.
See vault records
A browser extension paired per device
The Chromium extension fills logins on your action, offers to save or update records, and shows how many records match the active site. Each device pairs with a short-lived code and can be revoked from VaultPilot.
- Distributed through the Chrome Web Store
- Fleet rollout by published extension ID
- Encrypted snapshots and wrapped keys on the device

Share selected records with VaultPilot users or outside recipients
Internal recipients use their registered identities. External recipients get a passphrase-protected package that opens in a local browser, with an expiry date and a maximum number of opens. You can revoke an internal share from VaultPilot; an external package cannot be recalled once sent.
- Passphrase delivered through a separate channel
- Offline Share Decrypter ZIP offered on the result page

Optional Active Directory metadata sync
The DC Agent sends directory metadata and health signals to VaultPilot. The AD bind password is entered at the agent’s local prompt and is not sent to VaultPilot. You control enrollment and reconciliation.
- Separate scopes for login access and credential import
- Readiness and version checks
- Provider status, last sync, and base DN in view
- Password actions fail closed without managed-identity evidence

Discovery: a read-only review for secrets outside the vault
Approved users set the scope of each run: private IP ranges, TLS targets, and authorized local or SMB paths. A finding keeps a redacted excerpt and hashes, never the raw value. Only a file finding that a person has marked ready can be imported into a vault.
Read about Discovery
Audit history for supported actions
Sign-in, vault, sharing, extension, directory, update, and configuration events are recorded with the actor, target, role, and time. Each event carries its own hash and the hash of the event before it, so a reviewer can check the sequence.
Read about audit historyCertificate records with expiry alerts
Leaf certificates, chains, private keys, and PFX/P12 bundles are stored as encrypted vault records. VaultPilot reads X.509, PKCS#7, and PFX/P12 and alerts 15, 7, 3, and 1 day before expiry and on the expiry day.
Read about the certificate inventoryActive Directory password rotation
Rotation covers Active Directory credential records only. A connected DC Agent sets the new password in AD, and an authorized browser with the vault unlocked writes it into the encrypted record. Schedules run daily, weekly, monthly, or at a custom interval.
Read about AD password rotationAPI clients, email notifications, and import
Approved systems read encrypted snapshots and status through a read-only API. SMTP sends selected audit events to chosen inboxes. Import moves records from Bitwarden, LastPass, KeePass, 1Password, and Chrome. Only the Owner opens the Integrations screen.
See all integrations