Why VaultPilot
A team password manager that stays on your own Windows Server
Use VaultPilot when your vault cannot move to a vendor-hosted service. Check three things before you decide: where the data lives, what the product covers, and which work stays with your team.
Service, data, certificates and backups stay in your environment
VaultPilot installs on Windows Server and serves authorized browsers over HTTPS. Vault values are encrypted in the browser before they are saved; the server keeps encrypted records, wrapped keys, salts, and operational metadata in local SQLite.
- Installed from one MSI package
- No application runtime hosted by VaultPilot
- Your team owns the HTTPS certificate and the backups

One console for records, sharing, audit history, recovery, and optional integrations
The core is a vault for passwords, credentials, API keys, secure notes, certificates, and file-backed secrets. A paired Chromium extension, Discovery, selected-record sharing, audit history, recovery tools, API clients, and an optional directory agent build on that core. VaultPilot is not a general PAM, a SIEM, or a vulnerability scanner.
See the product features
What the product does and what stays with your team
VaultPilot enforces sign-in, roles, browser encryption, and update checks. Your team keeps the server patched, owns the HTTPS certificate and the off-host backups, and protects master passwords, authenticator devices, and agent tokens.
- Guides for installation, recovery, updates, and daily use
- Release notes and verification steps for every version