Keyvaci

Product & services

One product: team credential vaults,
done provably right

Keyvaci is not a platform, a suite, or an ecosystem. It is a vault for the credentials your organisation shares, built so that no one outside your organisation, including us, can ever read them.

Sign-in built for business

Two front doors, both built for a company

Most vaults bolt SSO on as an enterprise upsell. Keyvaci starts there and does not stop there: sign in with the directory your company already manages, or with a verified email address if you do not run one. Same vault, same encryption, same day-one price.

Available now

Microsoft Entra ID

Any organisation with Microsoft 365 or Entra ID can self-serve today:

  • A Global Administrator (or Privileged Role Administrator) of your tenant signs in with Microsoft and creates the organisation. We verify the role from Microsoft's own signed tokens, so nobody can create an organisation in your company's name without actually administering your directory.
  • Every member then signs in with their existing work account. No new passwords to distribute, no user list to upload.
  • Suspend someone in Entra ID and they lose access to Keyvaci with it. Your joiner-leaver process keeps working for the vault too.
  • Standards-based: OpenID Connect with PKCE, multi-tenant, access tokens verified against Microsoft's JWKS on every request.
Available now

Google Workspace

Workspace organisations sign in with Google in the web app. Creating the organisation requires a super administrator of that domain, checked against Google's own directory rather than taken on trust, and one domain maps to exactly one organisation. Personal Gmail is deliberately refused: without a directory there is nothing to attach an organisation to, so those users take the email route instead. Okta and generic OIDC are next, on the same seam.

Available now

Email + password, for teams without a directory

Smaller teams can sign up with any work email, verified by a one-time link. Signing in is a link too: enter your address and open the one we send, valid for five minutes and usable once. There is no sign-in password at all, so there is no second secret to reuse, forget or have stolen. Optional TOTP two-step verification, and an organisation can require it before a credential is revealed.

Why SSO does not break zero-knowledge here. Authentication and cryptography are fully separated in Keyvaci's design. Your identity provider answers "who are you"; it never touches "what can you decrypt". Keys are derived from each member's master password, on their device, regardless of how they signed in. Read the details in the security architecture.

Day-to-day

What your team gets

Vaults with three roles

Group credentials by system, client, or team. Each member of a vault is a reader, a writer, or an admin, and the server and the cryptography enforce the same rule.

Sharing with proof

Sharing encrypts the vault key for one recipient, only after their public key's organisation countersignature has been verified on your device. Signature fails, sharing stops.

Reveal with restraint

Credentials open with fresh authentication, auto-hide after seconds, and clear the clipboard after 30. Rate limits stop a stolen session from reading everything at once.

Search that stays local

Search vault names and entry names instantly. The index is built by decrypting on your machine, once per session, because the server has nothing readable to search.

Password health

Your organisation sets how many months a credential may go unchanged; stale entries are flagged. Every master password is gated by a strength check, not a lecture.

Five languages

English, Tiếng Việt, 日本語, 한국어, 中文, across the entire product, including every warning that protects your data.

Where it runs

Three clients, one implementation of the cryptography

A vault only works if it is open where the password is typed. Keyvaci ships a browser extension and a mobile app for iPhone and Android alongside the web console, and all three are built from the same encryption and the same signature checks rather than from three separate projects that have to be kept in agreement.

Browser extension

Chrome, Edge, and Brave. Click a password field and the menu opens under it, offering only credentials that belong to that site. Keys erase on a ten-minute deadline whether or not you come back, and copies clear from the clipboard after 30 seconds.

iPhone and Android apps

The full vault on the phone, plus a system password provider so Safari, Chrome and other apps can fill from it: iOS AutoFill on iPhone, Android Autofill on Android. Locks the instant you switch away. Biometric unlock is optional and off until you choose it.

Web console

Every browser, nothing to install. Where administrators run members, grants, rotation, recovery, and the audit log, and where Google Workspace sign-in is available today.

One master password opens all three, no client is a paid add-on, and every reveal reaches the same audit log wherever it happened. What each client does, and where each one is today →

For administrators

Control without custody

Administrators run the organisation. They still cannot read a vault they were not given. That distinction is the product.

Countersign new members

Confirm each member's key by comparing a short code over a separate channel, then countersign with the organisation signing key. Impersonation dies at this step.

Recovery you control

When someone forgets their master password, an administrator approves recovery with the organisation recovery key, generated in your browser at signup and never sent to us.

Revoke and rotate

Revoking vault access re-encrypts every entry under a new key, resumable if interrupted. Off-boarding means the old key stops working, mathematically.

Append-only audit

Who opened which vault, revealed which entry, shared and revoked what, and when. The log can be appended to, never edited, not even by us.

Organisation MFA policy

Require a second factor before any credential reveal, for members using email sign-in. Directory members follow the policy you already set in your IdP.

Billing that behaves

Pay for active seats only, prorated. Payment handled by Stripe; card details never touch Keyvaci. Lapsed subscription means read-only, never data loss.

See it with your own tenant

Setup takes minutes either way, and with Microsoft Entra ID it touches nothing else in your directory. Questions about a rollout, another IdP, or a larger team? We answer email quickly.