YOUR SECRETS, ON YOUR DEVICES
A vault you can use
every day.
Unlock with your passkey and this trusted device. Your encrypted secrets stay private on the server.
Restore or add a device
UNLOCKED ON THIS DEVICE
Your vault
Add or edit a secret
Verified workspace members
Trusted devices
Pair another device
Approve a scoped task
Each broker is one task. Confirm its full signing and encryption fingerprints through your trusted terminal. Only the selected field is sealed; task clients receive operation results.
Start the broker with this binding, then use the trusted human CLI to enroll its two keys. Enrollment never reveals a field.
Approved and expired grants
Protected CI runners
A separate protected controller authorizes each exact job. Runner keys never unlock the vault. Provision from this durable browser with a fresh passkey.
Run keyrail machine prove --profile /protected/machine.json < keyrail-machine-challenge.json > possession.json on the protected runner, then select its proof.
Encrypted backup
Workspace migration
Copy verified live items into a fresh encrypted workspace, then retire the original. Team members must be reenrolled.
Key rotation
Verify audit
Open encrypted export offline
Ready.