Integrations: where VaultPilot connects to other systems

Each documented connection point reaches a different system and carries a different kind of information. Turn on only the ones your installation needs and leave the rest off.

Integrations screen
Owner only
External write access
None through the API
Third-party lookups
Started by a user
The console linked to a browser extension, a directory agent, API clients and a mail server

What each connection carries

The browser extension receives vault keys wrapped for one approved device. The DC Agent sends directory and account state from the domain controller's network. API clients read encrypted snapshots or operational status. SMTP carries notification email and, when you choose it, external share packages.

Who opens the Integrations screen

Only the Owner sees the Integrations screen, and the license must include the Integration capability. The browser extension belongs to that same capability. Admin, Auditor and User cannot list or manage API clients or directory providers there.

Two lookups a user starts

The breach check on a password record sends only a short prefix of the password's hash to the HIBP Pwned Passwords service. The VirusTotal hash lookup on a stored file opens that file's SHA-256 page in a new tab. Neither runs on its own, and neither uploads the password or the file. The SHA-256 digest still reaches a third party, so check your policy first.

Where each connection is set up

Extension, API and DC Agent settings sit on the three tabs of the Integrations screen. SMTP connection details live under Server settings, while recipients and event rules live on Notifications. File import starts in Server settings and continues in a preview on the Passwords screen.