Blog · Strategy · 22 August 2026
Who builds your credential vault
Every vault vendor says the same four things. The interesting question is not what they claim, it is what the person who specified the product was accountable to for the twenty years before they built it.
A vault asks for more trust than software usually does
When you buy a project tool and the vendor turns out to be careless, you lose time. When you buy the place your company keeps its banking portal, its cloud root account and its clients' staging credentials, and the vendor turns out to be careless, you lose the company's ability to say who had access to what. That asymmetry is why every credential vault page reads the same: client-side encryption, zero knowledge, audit logs, revocation. The words are free.
So the useful question is not whether a vendor claims those properties. It is whether the person who decided what to build has ever had to prove them to somebody with the authority to say no.
Twenty years on the answering side of the questionnaire
Keyvaci is built by XNOR Group Pte. Ltd., a technology consulting company in Singapore. Its founder and chief executive, Ethan Pham, has spent more than twenty years delivering software for enterprise clients, which in practice means twenty years working inside somebody else's ISO-governed process: their access reviews, their security questionnaires, their procurement gates, their auditors.
That is a specific kind of experience, and it is not the same as knowing about security. A supplier who has answered enterprise security questionnaires for two decades has learned which answers a reviewer accepts and which ones they quietly downgrade you for. "We take security seriously" is the second kind. "Here is the control, here is where it does not apply, here is the evidence" is the first.
What an audit teaches that a feature list cannot
An enterprise audit is the one process that examines credential hygiene without being polite about it. Not what your policy says: who actually had access, when it was actually revoked, and whether there is a record or only an assurance.
A feature list cannot teach that lesson, because a feature list is written by the seller. An audit is the moment somebody with authority reads your access records and decides whether to believe them. Being on the answering side of that changes what you consider finished.
It is visible in Keyvaci's least exciting decisions. Revocation re-encrypts every entry with a new key rather than flipping a permission flag, because a flag is a promise and re-encryption is a fact. The audit trail is append-only through infrastructure permissions rather than application code, because an auditor's first question is whether the record can be edited by the thing it records. The security page publishes the model's limits next to its strengths, because a reviewer trusts a documented weakness more than a page of claims.
How to check a founder claim
None of the above is worth anything if you cannot check it, so it is all checkable. His professional profile, his company biography and his published writing in the Forbes Business Council are public, and the founder page links to all three.
XNOR Group Pte. Ltd. is incorporated in Singapore and its information security management system is certified to ISO/IEC 27001; the certificate and its scope are available on request. The architecture, including what it does not defend against, is on the security page.
And then judge the product rather than the biography. Fourteen days with everything unlocked is a stronger argument than any founder story.
Judge the product, not the pitch
Fourteen days, every feature, no card.