Product

Password and secrets management, from storage to the moment of use

One console on your own server covers vault records, the paired browser extension, selected-record sharing, Discovery, audit history, recovery, and optional Active Directory metadata sync.

Passwords, API keys, notes, certificates, and files

A record stays masked until an authorized user reveals or copies its value. The browser encrypts the secret before the server stores it.

See vault records
Conceptual illustration of protected record modules behind an authorization boundary

A browser extension paired per device

The Chromium extension fills logins on your action, offers to save or update records, and shows how many records match the active site. Each device pairs with a short-lived code and can be revoked from VaultPilot.

Read about the browser extension
Conceptual illustration of paired browser-extension device authorization

Share selected records with VaultPilot users or outside recipients

Internal recipients use their registered identities. External recipients get a passphrase-protected package that opens in a local browser, with an expiry date and a maximum number of opens. You can revoke an internal share from VaultPilot; an external package cannot be recalled once sent.

Read about sharing
Conceptual illustration of selected-record sharing through bounded recipient paths

Optional Active Directory metadata sync

The DC Agent sends directory metadata and health signals to VaultPilot. The AD bind password is entered at the agent’s local prompt and is not sent to VaultPilot. You control enrollment and reconciliation.

Read about Active Directory sync
Conceptual illustration of directory metadata synchronization across an agent boundary

Discovery: a read-only review for secrets outside the vault

Approved users set the scope of each run: private IP ranges, TLS targets, and authorized local or SMB paths. A finding keeps a redacted excerpt and hashes, never the raw value. Only a file finding that a person has marked ready can be imported into a vault.

Read about Discovery
Conceptual illustration of Discovery findings narrowing into reviewed evidence

Audit history for supported actions

Sign-in, vault, sharing, extension, directory, update, and configuration events are recorded with the actor, target, role, and time. Each event carries its own hash and the hash of the event before it, so a reviewer can check the sequence.

Read about audit history

Certificate records with expiry alerts

Leaf certificates, chains, private keys, and PFX/P12 bundles are stored as encrypted vault records. VaultPilot reads X.509, PKCS#7, and PFX/P12 and alerts 15, 7, 3, and 1 day before expiry and on the expiry day.

Read about the certificate inventory

Active Directory password rotation

Rotation covers Active Directory credential records only. A connected DC Agent sets the new password in AD, and an authorized browser with the vault unlocked writes it into the encrypted record. Schedules run daily, weekly, monthly, or at a custom interval.

Read about AD password rotation

API clients, email notifications, and import

Approved systems read encrypted snapshots and status through a read-only API. SMTP sends selected audit events to chosen inboxes. Import moves records from Bitwarden, LastPass, KeePass, 1Password, and Chrome. Only the Owner opens the Integrations screen.

See all integrations