Documentation: find the right guide from setup to recovery

Do not enter secrets, passwords, tokens, private hostnames, customer names, or unredacted incident data. Search state can appear in the page URL and request logs when the URL is opened or reloaded. Read the privacy notice.

47 articles

Guides

Active Directory and VaultPilot DC Agent Service

VaultPilot DC Agent Service runs near the domain controller and synchronizes directory metadata into VaultPilot.

Admin quickstart

The VaultPilot admin quickstart takes you from the official release download to a healthy first vault.

Audit and security posture

Use the VaultPilot Overview screen to turn health signals into a short, owned list of security actions.

Backups and restore

Their scope, key handling, and restore purpose are not interchangeable.

First run, owner and license

The first profile becomes the VaultPilot owner account. It is the account that manages users, licensing, security, and system settings.

In-app screen help

VaultPilot in-app screen help opens the matching help page for the active screen and language in a new tab.

Integration API clients

Use integration API clients when an approved system needs read-only VaultPilot data through the public API.

License lifecycle

VaultPilot license verification works offline: the server checks each license code with public verification material.

Operator runbook

This runbook lists the recurring VaultPilot checks after go-live, plus the incident and change-window routines.

Public API reference

VaultPilot public integration clients are read-only identities for approved systems.

Public host, HTTPS and certificates

VaultPilot uses HTTPS on the configured public port for browser access.

Release asset verification

Use this page before installing or redistributing a VaultPilot release asset.

Security and trust model

The VaultPilot security and trust model shows operators the trust boundaries, the assets they must protect and the update trust chain.

Server System settings

Use Server System when an Owner needs to review the server-facing settings that affect browser access, HTTPS trust, notifications, logs and maintenance.

Sharing and offline decrypter

VaultPilot sharing starts with the selected records. Operators package only the records and files they choose, not an entire vault.

Support evidence pack

The VaultPilot support evidence pack is a checklist for preparing a clear, redacted support case.

Troubleshooting

Each section lists the states, logs, and settings to check first. The MSI may be restarting the service.

Uninstall, data retention and rollback

Use this guide when an operator needs to remove VaultPilot from a Windows host, preserve server data, or roll back after a failed upgrade.

Update Center

VaultPilot Update Center manages the main Windows MSI package. The browser extension is installed and updated through the Chrome Web Store.

VaultPilot Browser Vault Extension

Installing the extension grants no access; each device must be paired and approved in VaultPilot.

VaultPilot Discovery

VaultPilot Discovery is a workspace where approved operators review exposure findings within an approved scope.

VaultPilot Overview

VaultPilot Enterprise Vault Console is a self-hosted, zero-knowledge enterprise vault console installed on Windows Server with an MSI.

Windows Server installation

Use this runbook for a normal VaultPilot Server installation or an in-place Windows upgrade, before you open the server to other users.

Screen guides

Active Directory records screen

The screen requires the Integration license feature and an unlocked active vault.

API keys screen

Marking a VaultPilot record revoked does not revoke the real key at its provider.

Audit Log screen

The Audit Log shows each event's actor, affected target, role, timestamp, operation details, and integrity hashes.

Browser extension screen

The Browser Extension screen under Integrations Browser extension shows the Chrome Web Store channel and the paired browser profiles.

Certificate dashboard screen

The Certificate Dashboard summarizes certificate records in the active vault by validity, status, certificate authority, origin, and organization.

Certificates screen

The Certificates screen manages certificate, certificate-package, and private-key records in the selected vault.

Discovery screen

Discovery is a workspace for reviewing approved private-network, TLS, and file-exposure checks.

Domain screen

The Domain dashboard brings four widgets with different data sources into one view.

Executions screen

Executions combines update jobs, AD agent actions, and selected audit events in one time-ordered view.

Files screen

The Files screen manages file records in the active vault; it is not a general document archive, network share, or cloud-storage client.

Integrations screen

The Integrations screen manages three product surfaces: External API clients, the Active Directory DC Agent, and the Browser extension.

License screen

The License screen brings together the verified plan, active-user capacity, remaining term, write availability, and included capabilities.

New item screen

The New item editor opens from the global topbar Add new record control after you choose Password, API key, Secure note, Certificate, or File.

Notifications screen

The Notifications screen controls which audit events can be sent by SMTP email and which addresses receive them.

Passwords screen

The Passwords screen is for finding and reviewing password records in the active vault, and editing them when your access permits it.

Rotation dashboard screen

The Rotation dashboard is a read-only prioritization view built from credential inventory, audit records, and Active Directory agent actions.

Secure notes screen

The Secure Notes screen stores protected operational text that does not belong in a password, API key, certificate, or file record.

Security Command Center Screen

The Security Command Center screen brings the security score, priority recommendations, server readiness, and operational signals into one workspace.

Security screen

The Security screen shows which record, behavior, or access signal deserves investigation rather than reducing security to one score.

Server settings screen

The Server Settings screen groups the General, Access & HTTPS, SMTP, Maintenance & Logs, and Sign-in security tabs.

Sharing screen

External sharing is not a hosted portal, public link, or central PAM checkout service.

Sign-in security screen

Sign-in security manages the unlocked personal profile's master-password change, TOTP-based 2FA binding, and, for the Owner, active server sessions.

Updates screen

The Updates screen checks local or signed remote evidence for the VaultPilot server MSI and starts an eligible installation job.

Users screen

The Users screen lists local and Active Directory-backed users with their global roles, account and 2FA state, and each user's vault-grant count.