Keyvaci

Zero-knowledge credential vault for teams

We store your team's secrets.
No one else can read them, not even us.

14-day free trial · every feature · up to 10 people · no credit card

Your device Keyvaci
Your device plaintext
name
secret
master password → Argon2id · 64 MiB → key
nothing readable crosses here
Keyvaci server waiting
stored as ciphertext · we hold no key

01 · You write a secret on your own machine

XChaCha20-Poly1305 Argon2id · 64 MiB X25519 + Ed25519 Ciphertext-only storage ISO/IEC 27001 certified operator Verified publisher · Microsoft Entra ID

From sign-up to off-boarding

Central control of every company credential

Work logins scatter across personal password managers and chat threads. Keyvaci gathers them into one vault your administrators run and we cannot read.

Administration 6 people · 3 vaults
ADMIN SM Sarah Banking · Engineering · Project DK David Engineering · Project EC Emma Project JR James Banking · Project PS Priya Engineering LO Lucas Banking · Engineering
Banking secrets Engineering secrets Project secrets
who can open what, at a glance

01 · Invite the team with the accounts they already have

The XNOR Group team, who build Keyvaci, working together around a shared table

Built for teams, not power users

What changes when the whole team is in one vault

The XNOR Group team. They have used Keyvaci every day since before you could.

  1. One password to remember, not forty

  2. Logins fill themselves, in any browser and on any phone

  3. No one has to ask a colleague to send a password again

Where the vault meets the workday

Central control is only half of it

01 · In the console

In the console

Members, vaults, grants, rotation, recovery and the audit log, from any browser with nothing to install. This is where access is given, and where it is taken back.

Keyvaci console · any browser

02 · In the browser

In the browser

Install Keyvaci's browser extension. Click a password field and the Keyvaci menu opens under it. Pick the entry and it fills. No tab switch, nothing on the clipboard.

bank.northwind.example
Clicking the password field on a sign-in page, choosing the Keyvaci entry, and both fields filling

03 · On the phone

On the phone

The whole company vault in your pocket. iPhone and Android run the same encryption as the desktop, at full strength, and lock the instant you switch to another app.

9:41 Keyvaci for iPhone and Android
Keyvaci console · any browser
Keyvaci console · any browser
bank.northwind.example
Clicking the password field on a sign-in page, choosing the Keyvaci entry, and both fields filling
Keyvaci extension · Chrome, Edge, Brave
9:41 Keyvaci for iPhone and Android
Keyvaci for iPhone and Android

All three share one implementation of the encryption and one implementation of the signature checks, so there is no second, weaker copy of the cryptography to keep in agreement. One master password opens all of them, and every reveal lands in the same audit log wherever it happened.

Security is the product

Absolute claims, checkable design

Zero-knowledge, literally

Encryption happens on your device before anything is sent. We hold ciphertext, never keys. A breach here produces no plaintext, because none exists.

The master password never travels

Used once on your machine to derive your keys, with Argon2id at 64 MiB. Never sent, never stored, and we cannot reset it.

Countersigned keys

The organisation signs every member's key before a vault can be shared. A fake recipient fails that check on your device.

Step-up before every reveal

Reading a credential needs fresh authentication, with optional TOTP. A hijacked session cannot quietly drain a vault.

Append-only audit trail

Every reveal, share and revocation goes to a log the API cannot update or delete. Its credentials only allow appending.

Revocation that means it

Removing someone re-encrypts every entry under a new key. Their old key becomes useless mathematics, not a flag someone forgot to flip.

Trusted by

Organisations that run on Keyvaci

Pricing

Not everyone needs every vault

Most people live in one or two shared vaults. A few administer everything. Pay for each person's actual access.

Standard for the many who work from one or two vaults. Premium for admins and anyone who needs more. Mix them, move anyone, any day.

Standard

$3 /member/month

$30.60/member/yearSave 15%

  • Up to 2 vaults per member
  • Unlimited entries
  • All security features included
Start free trial

14-day trial with everything unlocked for up to 10 people, no credit card. When it ends, your data goes read-only, never away. Full pricing details →

Questions teams ask

Frequently asked questions

Who is behind Keyvaci?

Keyvaci is built and operated by XNOR Group Pte. Ltd., a technology company in Singapore that builds software products and consults for enterprises, and whose information security management system is certified to ISO/IEC 27001. Its founder and chief executive, Ethan Pham, has spent more than twenty years delivering software for enterprise clients under ISO-governed process, answering their access reviews, security questionnaires and audits from the supplier side. His background, and the product decisions it forced, are set out on the founder page.

What does "zero-knowledge" actually mean in Keyvaci?

Encryption and decryption happen only on your devices, with keys derived from master passwords we never receive. Our servers store and serve ciphertext. Even with full database access, neither Keyvaci staff nor an attacker could read your credentials, because the material needed to decrypt them never reaches us.

If you can't read anything, what happens when someone forgets their master password?

Your organisation recovers them, not us. At signup, your browser generates an organisation recovery key that only you hold. An administrator uses it to approve a recovery request, and the member sets a new master password. Keyvaci remains unable to read anything at every step of that process.

Which single sign-on providers are supported?

Microsoft Entra ID and Google Workspace are both supported today: your team signs in with the work accounts it already has, and creating the organisation is limited to someone who genuinely administers that directory. Okta and generic OpenID Connect are next. Teams without a directory can use email sign-up with mandatory verification, which carries exactly the same encryption.

What happens when the trial or subscription ends?

The organisation becomes read-only. You can still sign in, read, and export everything; recovery for forgotten passwords keeps working too. Write access returns the moment a plan is active. We treat "your data stays yours" as a hard rule, not a retention tactic.

Can Keyvaci hand my credentials to authorities, or lose them in a breach?

We can only ever hand over what we have, and what we have is ciphertext. The same applies to a breach of our infrastructure: the plaintext of your vaults, and the keys to them, exist only on your devices.

How is Keyvaci different from other password managers?

Keyvaci is business-only and SSO-first: no consumer app, no feature maze, one product that does team credential vaults with verifiable cryptography, at a fraction of typical per-seat prices. Every security feature ships in every plan, and if you ever stop paying, your data goes read-only, never away.

Your credentials, sealed in 14 days of trying

Sign in with company SSO or an email address, create your first vault, and invite the team. If it is not obviously better, walk away with your data; it was always readable only by you.