Founder
The person accountable for Keyvaci
Keyvaci is operated by XNOR Group Pte. Ltd. Its founder and chief executive is Ethan Pham (Phạm Sĩ Nguyên), who has spent more than twenty years building software for enterprise clients. This page is here because a vault asks for more trust than most software, and you are entitled to know who is asking.
Twenty years of audits, and a certificate of his own
Ethan holds a Master's in Information Technology from Swinburne University of Technology in Australia and a Bachelor's in Electrical Engineering from Vietnam National University. Before founding XNOR Group he held senior consulting, architecture and leadership roles at multiple Australian and Singaporean companies and he co-founded Enouvo IT Solutions, serving as its CTO, then CIO and finally CEO as it grew from a local startup in Danang, Vietnam into a global software development provider. He works across all three countries. He is also an active writer for the Forbes Business Council, publishing regularly on enterprise technology leadership, AI governance and software delivery.
The detail that matters for a product like this one is not the job titles. It is that twenty of those years were spent delivering for enterprise clients, which means twenty years of working inside somebody else's ISO-governed process: their access reviews, their security questionnaires, their procurement gates, their auditors. He has answered those questions from the supplier's side of the table for two decades, so he knows what an enterprise buyer will ask about a credential vault before they ask it.
And he does not only comply with other people's standards. He runs XNOR Group's own information security management system, certified to ISO/IEC 27001 & 9001, which means he is the person accountable for the scope, the risk assessment, the controls and the surveillance audits rather than the person answering questions about somebody else's. Specifying a vault is a different exercise when you are the one who will have to show an auditor how it works.
Why a consulting founder built a vault
XNOR Group is a technology consulting company. That means dozens of shared logins: client staging servers, cloud root accounts, registrar and DNS accounts, banking portals. The credentials a consultancy holds are not its own, which raises the stakes on every one of them.
The tools built for this job had grown into identity platforms priced and shaped for companies with procurement departments, and the honest alternatives all asked to be trusted. So Keyvaci was built for XNOR first, and the rule was set before the first line of code: the vendor's inability to read customer data has to be a property of the mathematics, not a paragraph in a policy.
Trust should be a design decision, not a request.
Ethan Pham
What twenty years of enterprise delivery put into the product
| Where it comes from | What it became in Keyvaci |
|---|---|
| Running an ISO/IEC 27001 certified management system, not just complying with one | An append-only audit trail enforced by infrastructure permissions rather than application code, because an auditor's first question is whether the record can be edited by the thing it records |
| Enterprise security questionnaires, answered for two decades | A security page that publishes the model's limits alongside its strengths, and a threat model with numbered findings tracked to closure, because a reviewer trusts a documented weakness more than a page of strengths |
| Access and offboarding examined by somebody else's auditor | Revocation that re-encrypts every entry with a new key, so a removed member's copy stops working, rather than a permission flag somebody has to remember to switch off |
| A consultancy holding other companies' credentials | Per-vault roles, reveal-time re-authentication, and a record of every reveal, because the answer to "who saw this" cannot be "probably nobody" |
| Procurement gates that punish surprises | Every security feature in every plan, published pricing, versioned legal documents, and read-only rather than deletion when a subscription lapses |
None of that is a feature list. It is what happens when the person specifying a vault has spent twenty years being audited rather than twenty years selling to people who are.
Check it yourself
Everything above is verifiable, which is the point. His professional profile, the company biography and his published writing are all public.
XNOR Group Pte. Ltd. is incorporated in Singapore and its information security management system is certified to ISO/IEC 27001; the certificate and its scope are available on request through the contact page. The architecture, including what it does not protect against, is on the security page.
Ask him a hard question
The people who answer are the people who built it. A fourteen-day trial is a better argument than any founder page.