Search VaultPilot resources
Search VaultPilot's product, security, deployment, screen-help, and troubleshooting pages.
Do not enter secrets, passwords, tokens, private hostnames, customer names, or unredacted incident data. Search state can appear in the page URL and request logs when the URL is opened or reloaded. Read the privacy notice.
105 results
Site page
A static site with no tracking before consent and no form collection
How the VaultPilot website handles data: a local email helper, no remote form collection, and analytics that stay off until you accept them.Site page
A team password manager that stays on your own Windows Server
Why security and IT leads evaluate VaultPilot as a self-hosted password manager for teams: browser encryption, your own Windows Server and recovery.Site page
A zero-knowledge secrets manager for teams that run Windows Server
VaultPilot is a zero-knowledge secrets manager for teams on Windows Server. Secrets are encrypted in the browser and stored on a server you control.Documentation
Active Directory and VaultPilot DC Agent Service
VaultPilot DC Agent Service runs near the domain controller and synchronizes directory metadata into VaultPilot.Documentation
Active Directory records screen
The screen requires the Integration license feature and an unlocked active vault.Product guidance
Active Directory: add directory context without sending AD passwords
The optional VaultPilot DC Agent runs next to the domain controller and sends approved directory and health information. Neither the AD bind password nor AD user passwords go to VaultPilot.Product guidance
AD password rotation: rotate passwords through an agent you run
Rotation in VaultPilot applies to Active Directory credential records only. A connected DC Agent generates the new password, sets it in AD and returns it encrypted to a VaultPilot public key. An authorized browser with the vault unlocked then writes it into the encrypted record.Documentation
Admin quickstart
The VaultPilot admin quickstart takes you from the official release download to a healthy first vault.Documentation
API keys screen
Marking a VaultPilot record revoked does not revoke the real key at its provider.Documentation
Audit and security posture
Use the VaultPilot Overview screen to turn health signals into a short, owned list of security actions.Knowledge base
Audit chain is partial or inconsistent
The Audit Log screen can report a partial chain, an inconsistent hash sequence, missing rows after restore, or a chain warning the filters cannot explain.Product guidance
Audit history: trace what happened, event by event
VaultPilot records supported authentication, vault, sharing, extension, directory, update, configuration, and security events with their context. Keep audit exports and event details private, and redact anything you share.Documentation
Audit Log screen
The Audit Log shows each event's actor, affected target, role, timestamp, operation details, and integrity hashes.Product guidance
Backup and recovery: match the recovery file to the failure
VaultPilot has two recovery files. Quick Recovery is a browser-encrypted package that restores a profile and its accessible non-file records. The Backup Tool archive is the full VaultPilot server backup.Knowledge base
Backup import fails or closes sessions
Use this article when a VaultPilot backup import fails, returns an archive error, rejects an oversized upload, or succeeds and closes active sessions.Documentation
Backups and restore
Their scope, key handling, and restore purpose are not interchangeable.Documentation
Browser extension screen
The Browser Extension screen under Integrations Browser extension shows the Chrome Web Store channel and the paired browser profiles.Product guidance
Browser extension: fill approved records from a paired browser
The VaultPilot Browser Vault Extension pairs a named browser device with your VaultPilot server. An Owner approves and revokes each device in the VaultPilot console.Documentation
Certificate dashboard screen
The Certificate Dashboard summarizes certificate records in the active vault by validity, status, certificate authority, origin, and organization.Product guidance
Certificate management: track certificates before they expire
The certificate inventory keeps leaf certificates, chains, private keys and PFX/P12 bundles as encrypted records in a vault. It is separate from the HTTPS certificate that VaultPilot itself serves, which you manage in Server settings.Documentation
Certificates screen
The Certificates screen manages certificate, certificate-package, and private-key records in the selected vault.Product guidance
Data boundaries: know what crosses each one before you share
VaultPilot keeps separate data boundaries for browser access, local storage, paired extensions, the optional DC Agent, external packages, update files, and support information.Knowledge base
DC Agent service troubleshooting
Use this article when VaultPilot DC Agent Service cannot install, connect, sync, or recover.Site page
Deploy a self-hosted password manager on Windows Server
How the VaultPilot Windows Server password manager is installed: MSI setup, HTTPS access, first run, backup duties and the verified update path.Product guidance
Directory agent: run it close to the domain controller
VaultPilot DC Agent Service is a Windows service that runs close to the domain controller. It syncs OU, group, and user metadata from the directory into VaultPilot. The AD bind password stays on the machine that runs the agent.Documentation
Discovery screen
Discovery is a workspace for reviewing approved private-network, TLS, and file-exposure checks.Product guidance
Discovery: find exposed secrets without collecting them
With VaultPilot Discovery, approved users review private-network login pages, certificate risks, and authorized files. The aim is to find secrets that may sit outside the encrypted vault.Site page
Documentation, troubleshooting and releases
VaultPilot docs and support: v3.0.3 guides in English and Turkish, the troubleshooting knowledge base, and release files with sizes and SHA-256.Product guidance
Documentation: find the right guide from setup to recovery
The documentation is organized by task and written for administrators, security operators, and support teams. Start with installation and the security model. Move to task and screen guides for daily work, and to recovery and troubleshooting when something breaks.Documentation
Domain screen
The Domain dashboard brings four widgets with different data sources into one view.Product guidance
Email notifications: send selected audit events to the right inbox
VaultPilot can email selected audit events through an SMTP server that the Owner sets up. Each event has its own delivery rule, and one recipient list receives the mail. Every event stays in audit history whether or not it is emailed.Product guidance
Encrypted sharing: send selected records inside or outside the team
VaultPilot shares in two ways: an encrypted bundle for registered internal users, and a passphrase-protected package for people outside the server. Either way, you pick the records and the recipient. You can revoke only an internal share later; once you send an external package, you cannot take it back centrally.Site page
Evaluate a zero-knowledge secrets manager on your Windows Server
An enterprise password manager technical evaluation of VaultPilot: Windows Server deployment, browser encryption, roles, sharing, recovery and updates.Site page
Everyday credential work without replacing your security stack
How security and IT teams use VaultPilot for shared credentials, certificates, file-backed secrets, record sharing, recovery and directory metadata.Documentation
Executions screen
Executions combines update jobs, AD agent actions, and selected audit events in one time-ordered view.Knowledge base
Extension pairing remains pending
Use this when the Chromium extension is installed but the VaultPilot panel remains pending, does not show the device, or pairs once and then stops syncing.Knowledge base
External share package fails to open
Check package integrity and recipient handling before recreating a share.Documentation
Files screen
The Files screen manages file records in the active vault; it is not a general document archive, network share, or cloud-storage client.Documentation
First run, owner and license
The first profile becomes the VaultPilot owner account. It is the account that manages users, licensing, security, and system settings.Site page
Frequently asked questions about VaultPilot
Five short answers for evaluators: cloud or self-hosted, where the master password and data go, how an unsigned MSI update is verified, file sharing.Site page
Get support for VaultPilot
VaultPilot support: documentation and the knowledge base first, in-product screen help, support@vaultpilot.io for your case, a separate security report.Site page
How VaultPilot compares with self-hosted password managers
How VaultPilot differs from Bitwarden, Passbolt, Psono, Password Depot and five other products on deployment, encryption and primary job, from vendor docs.Knowledge base
HTTPS certificate warning
Use this article when users see a browser warning after VaultPilot HTTPS is enabled.Product guidance
HTTPS certificates: the certificate must name the host users open
VaultPilot starts with a self-signed certificate it manages itself, so you can reach it on first access. For broad use you upload a PFX/P12 package issued by your organization. The certificate in that package has to match the DNS name or IP address users actually open.Product guidance
Import and migration: move records from another password manager
Import starts in Server settings under Import & migration. The browser reads the export file and opens a preview on the Passwords screen. Nothing is saved until you confirm the final step in an unlocked vault.Documentation
In-app screen help
VaultPilot in-app screen help opens the matching help page for the active screen and language in a new tab.Product guidance
Install and first run: from a verified MSI to the first Owner session
You install VaultPilot on Windows Server from an MSI package. Users reach it in the browser through the server's HTTPS address. The first profile you create becomes the Owner account, and that account finishes the remaining setup.Knowledge base
Integration API client gets 401, scope denied, or no data
Use this article when an integration API client receives 401 or a scope-denied response, or gets an empty encrypted snapshot.Documentation
Integration API clients
Use integration API clients when an approved system needs read-only VaultPilot data through the public API.Documentation
Integrations screen
The Integrations screen manages three product surfaces: External API clients, the Active Directory DC Agent, and the Browser extension.Product guidance
Integrations: where VaultPilot connects to other systems
Each documented connection point reaches a different system and carries a different kind of information. Turn on only the ones your installation needs and leave the rest off.Product guidance
Knowledge base: start from the symptom, take one safe step
The knowledge base covers problems during and after installation. Find the symptom you see in the table below and begin with its first safe check.Documentation
License lifecycle
VaultPilot license verification works offline: the server checks each license code with public verification material.Knowledge base
License read-only state
Read-only mode is a controlled safety state; do not bypass it with database edits or unsupported configuration changes.Documentation
License screen
The License screen brings together the verified plan, active-user capacity, remaining term, write availability, and included capabilities.Knowledge base
MSI installation fails
Use this checklist if the VaultPilot MSI does not complete or the service does not start after installation.Documentation
New item screen
The New item editor opens from the global topbar Add new record control after you choose Password, API key, Secure note, Certificate, or File.Documentation
Notifications screen
The Notifications screen controls which audit events can be sent by SMTP email and which addresses receive them.Site page
One address, and only the details the case needs
Reach VaultPilot at support@vaultpilot.io for an evaluation, a documentation question, support routing, or a private path for sensitive case details.Product guidance
Operator responsibilities: product controls and your team's part
VaultPilot runs on your own server. Your team looks after identities, endpoints, HTTPS, certificates, backups, updates, agents, recovery material, and support information.Documentation
Operator runbook
This runbook lists the recurring VaultPilot checks after go-live, plus the incident and change-window routines.Site page
Password and secrets management, from storage to the moment of use
VaultPilot features: vault records, the browser extension, record sharing, Discovery, audit history, recovery tools and optional Active Directory sync.Documentation
Passwords screen
The Passwords screen is for finding and reviewing password records in the active vault, and editing them when your access permits it.Documentation
Public API reference
VaultPilot public integration clients are read-only identities for approved systems.Documentation
Public host, HTTPS and certificates
VaultPilot uses HTTPS on the configured public port for browser access.Product guidance
Read-only API: approved systems read, never plaintext
An API client is a read-only identity for one approved system. The Owner chooses its scopes and, when vault data is needed, the vaults it may read. Vault data comes back only as encrypted snapshots; the API never returns plaintext passwords or decrypted vault data.Knowledge base
Redacting support evidence
Use this article to redact screenshots, logs and error details before you email them to VaultPilot support at support@vaultpilot.io.Documentation
Release asset verification
Use this page before installing or redistributing a VaultPilot release asset.Product guidance
Release details: VaultPilot 3.0.3 files and checksums
Each VaultPilot release comes with release notes, an Ed25519-signed update manifest, and a published file list. Download the files only from the official release and verify them before you install.Site page
Releases, dates, and release notes
VaultPilot and PassMan-era versions from 1.7.0 to 3.0.3 with release dates, publication status, a direct installer download and each version's notes.Knowledge base
Repeated 401 or 403 errors after sign-in
Use this article when screens such as Audit Log, Passwords, Updates, Users or Browser Extension show access errors or empty data right after login.Product guidance
Responsible disclosure: report security issues privately
Report a suspected vulnerability privately to support@vaultpilot.io, as a separate security report. Never post exploit details, secrets, customer data, credentials, tokens, certificates, databases, or backups anywhere public.Knowledge base
Reviewing Discovery findings
Use this when Discovery reports a secret exposure signal, import is disabled, or an operator is unsure if a finding should become a vault record.Documentation
Rotation dashboard screen
The Rotation dashboard is a read-only prioritization view built from credential inventory, audit records, and Active Directory agent actions.Documentation
Secure notes screen
The Secure Notes screen stores protected operational text that does not belong in a password, API key, certificate, or file record.Documentation
Security and trust model
The VaultPilot security and trust model shows operators the trust boundaries, the assets they must protect and the update trust chain.Documentation
Security Command Center Screen
The Security Command Center screen brings the security score, priority recommendations, server readiness, and operational signals into one workspace.Documentation
Security screen
The Security screen shows which record, behavior, or access signal deserves investigation rather than reducing security to one score.Knowledge base
Server settings need a restart or maintenance review
Use this if VaultPilot Server System settings were saved but browser access, HTTPS, notifications, logs, or service restart state still need review.Documentation
Server settings screen
The Server Settings screen groups the General, Access & HTTPS, SMTP, Maintenance & Logs, and Sign-in security tabs.Documentation
Server System settings
Use Server System when an Owner needs to review the server-facing settings that affect browser access, HTTPS trust, notifications, logs and maintenance.Documentation
Sharing and offline decrypter
VaultPilot sharing starts with the selected records. Operators package only the records and files they choose, not an entire vault.Documentation
Sharing screen
External sharing is not a hosted portal, public link, or central PAM checkout service.Documentation
Sign-in security screen
Sign-in security manages the unlocked personal profile's master-password change, TOTP-based 2FA binding, and, for the Owner, active server sessions.Product guidance
Sign-in security: master password, TOTP, and sessions
VaultPilot signs you in with a username, your master password and, once you enable it, a six-digit code from an authenticator app. On the Sign-in security tab you change the master password, set up or revoke two-step verification and, as Owner, end other sessions.Documentation
Support evidence pack
The VaultPilot support evidence pack is a checklist for preparing a clear, redacted support case.Product guidance
Support evidence: give enough context, not the environment
A useful support request opens with a short case summary. It then adds only the redacted observations for the affected area. Send a backup only if an approved private channel explicitly asks for it. Never send the database, secret values, access tokens, private keys, certificate packages, or unredacted screenshots.Documentation
Troubleshooting
Each section lists the states, logs, and settings to check first. The MSI may be restarting the service.Documentation
Uninstall, data retention and rollback
Use this guide when an operator needs to remove VaultPilot from a Windows host, preserve server data, or roll back after a failed upgrade.Documentation
Update Center
VaultPilot Update Center manages the main Windows MSI package. The browser extension is installed and updated through the Chrome Web Store.Knowledge base
Update stays around 76 percent
The 76 percent stage usually means VaultPilot has verified the release manifest and MSI package, then entered the quiet Windows Installer phase.Product guidance
Update verification: check each release's manifest, hash and size
For v3.0.3, VaultPilot installs the unsigned MSI from the official release only when the Ed25519-signed manifest, allowed host, filename, SHA-256, and file size all agree.Documentation
Updates screen
The Updates screen checks local or signed remote evidence for the VaultPilot server MSI and starts an eligible installation job.Product guidance
Updates: back up, verify, install, then check
Update Center verifies and installs the package. You take the backup first, read the verification result before you approve the install, and check the system once the service is back. Only an Owner on a writable license can start the install.Product guidance
Users and roles: global and vault roles decide who sees what
Every VaultPilot account has one global role for the console and, in each vault it can reach, a separate vault role. Only the Owner and Admin open the Users screen. That screen assigns Admin, Auditor or User and never creates another Owner.Documentation
Users screen
The Users screen lists local and Active Directory-backed users with their global roles, account and 2FA state, and each user's vault-grant count.Product guidance
Vault records: passwords, keys, notes, certificates, and files
The browser encrypts each record before it is saved. The list shows each record's name, type, and lifecycle details. The secret value stays masked until someone with access opens it.Documentation
VaultPilot Browser Vault Extension
Installing the extension grants no access; each device must be paired and approved in VaultPilot.Documentation
VaultPilot Discovery
VaultPilot Discovery is a workspace where approved operators review exposure findings within an approved scope.Documentation
VaultPilot Overview
VaultPilot Enterprise Vault Console is a self-hosted, zero-knowledge enterprise vault console installed on Windows Server with an MSI.Site page
VaultPilot: a self-hosted secrets manager for Windows Server
What VaultPilot is, which release this site describes, and how its self-hosted Windows Server password manager is documented for administrators and users.Site page
What the zero-knowledge design protects, and what it does not
What VaultPilot's zero-knowledge design covers: browser, server, storage, extension, sharing and update boundaries, and what your team must protect.Site page
What you need before installing VaultPilot
What VaultPilot v3.0.3 needs: the Windows Server host, the software the MSI installs, HTTPS and network prerequisites, Chromium clients and the DC Agent.Documentation
Windows Server installation
Use this runbook for a normal VaultPilot Server installation or an in-place Windows upgrade, before you open the server to other users.Product guidance
Zero knowledge: the vault unlocks in the browser session
As a zero-knowledge encryption password manager, VaultPilot encrypts vault data in the browser before the server stores it. The server authenticates requests and keeps encrypted payloads, wrapped keys, salts, and operational metadata. Unlocked vault keys exist only in the browser's session memory.No resource matches this search. Try a shorter problem, task, or feature name.