01 · In the console
In the console
Members, vaults, grants, rotation, recovery and the audit log, from any browser with nothing to install. This is where access is given, and where it is taken back.

Zero-knowledge credential vault for teams
14-day free trial · every feature · up to 10 people · no credit card
01 · You write a secret on your own machine
From sign-up to off-boarding
Work logins scatter across personal password managers and chat threads. Keyvaci gathers them into one vault your administrators run and we cannot read.
01 · Invite the team with the accounts they already have
Built for teams, not power users
The XNOR Group team. They have used Keyvaci every day since before you could.
Where the vault meets the workday
01 · In the console
Members, vaults, grants, rotation, recovery and the audit log, from any browser with nothing to install. This is where access is given, and where it is taken back.

02 · In the browser
Install Keyvaci's browser extension. Click a password field and the Keyvaci menu opens under it. Pick the entry and it fills. No tab switch, nothing on the clipboard.
03 · On the phone
The whole company vault in your pocket. iPhone and Android run the same encryption as the desktop, at full strength, and lock the instant you switch to another app.

All three share one implementation of the encryption and one implementation of the signature checks, so there is no second, weaker copy of the cryptography to keep in agreement. One master password opens all of them, and every reveal lands in the same audit log wherever it happened.
Security is the product
Encryption happens on your device before anything is sent. We hold ciphertext, never keys. A breach here produces no plaintext, because none exists.
Used once on your machine to derive your keys, with Argon2id at 64 MiB. Never sent, never stored, and we cannot reset it.
The organisation signs every member's key before a vault can be shared. A fake recipient fails that check on your device.
Reading a credential needs fresh authentication, with optional TOTP. A hijacked session cannot quietly drain a vault.
Every reveal, share and revocation goes to a log the API cannot update or delete. Its credentials only allow appending.
Removing someone re-encrypts every entry under a new key. Their old key becomes useless mathematics, not a flag someone forgot to flip.
Trusted by
Pricing
Most people live in one or two shared vaults. A few administer everything. Pay for each person's actual access.
Standard for the many who work from one or two vaults. Premium for admins and anyone who needs more. Mix them, move anyone, any day.
$3 /member/month
$30.60/member/yearSave 15%
$6 /member/month
$61.20/member/yearSave 15%
14-day trial with everything unlocked for up to 10 people, no credit card. When it ends, your data goes read-only, never away. Full pricing details →
Questions teams ask
Keyvaci is built and operated by XNOR Group Pte. Ltd., a technology company in Singapore that builds software products and consults for enterprises, and whose information security management system is certified to ISO/IEC 27001. Its founder and chief executive, Ethan Pham, has spent more than twenty years delivering software for enterprise clients under ISO-governed process, answering their access reviews, security questionnaires and audits from the supplier side. His background, and the product decisions it forced, are set out on the founder page.
Encryption and decryption happen only on your devices, with keys derived from master passwords we never receive. Our servers store and serve ciphertext. Even with full database access, neither Keyvaci staff nor an attacker could read your credentials, because the material needed to decrypt them never reaches us.
Your organisation recovers them, not us. At signup, your browser generates an organisation recovery key that only you hold. An administrator uses it to approve a recovery request, and the member sets a new master password. Keyvaci remains unable to read anything at every step of that process.
Microsoft Entra ID and Google Workspace are both supported today: your team signs in with the work accounts it already has, and creating the organisation is limited to someone who genuinely administers that directory. Okta and generic OpenID Connect are next. Teams without a directory can use email sign-up with mandatory verification, which carries exactly the same encryption.
The organisation becomes read-only. You can still sign in, read, and export everything; recovery for forgotten passwords keeps working too. Write access returns the moment a plan is active. We treat "your data stays yours" as a hard rule, not a retention tactic.
We can only ever hand over what we have, and what we have is ciphertext. The same applies to a breach of our infrastructure: the plaintext of your vaults, and the keys to them, exist only on your devices.
Keyvaci is business-only and SSO-first: no consumer app, no feature maze, one product that does team credential vaults with verifiable cryptography, at a fraction of typical per-seat prices. Every security feature ships in every plan, and if you ever stop paying, your data goes read-only, never away.
Sign in with company SSO or an email address, create your first vault, and invite the team. If it is not obviously better, walk away with your data; it was always readable only by you.