Product & services
One product: team credential vaults,
done provably right
Keyvaci is not a platform, a suite, or an ecosystem. It is a vault for the credentials your organisation shares, built so that no one outside your organisation, including us, can ever read them.
Sign-in built for business
Two front doors, both built for a company
Most vaults bolt SSO on as an enterprise upsell. Keyvaci starts there and does not stop there: sign in with the directory your company already manages, or with a verified email address if you do not run one. Same vault, same encryption, same day-one price.
Microsoft Entra ID
Any organisation with Microsoft 365 or Entra ID can self-serve today:
- A Global Administrator (or Privileged Role Administrator) of your tenant signs in with Microsoft and creates the organisation. We verify the role from Microsoft's own signed tokens, so nobody can create an organisation in your company's name without actually administering your directory.
- Every member then signs in with their existing work account. No new passwords to distribute, no user list to upload.
- Suspend someone in Entra ID and they lose access to Keyvaci with it. Your joiner-leaver process keeps working for the vault too.
- Standards-based: OpenID Connect with PKCE, multi-tenant, access tokens verified against Microsoft's JWKS on every request.
Google Workspace
Workspace organisations sign in with Google in the web app. Creating the organisation requires a super administrator of that domain, checked against Google's own directory rather than taken on trust, and one domain maps to exactly one organisation. Personal Gmail is deliberately refused: without a directory there is nothing to attach an organisation to, so those users take the email route instead. Okta and generic OIDC are next, on the same seam.
Email + password, for teams without a directory
Smaller teams can sign up with any work email, verified by a one-time link. Signing in is a link too: enter your address and open the one we send, valid for five minutes and usable once. There is no sign-in password at all, so there is no second secret to reuse, forget or have stolen. Optional TOTP two-step verification, and an organisation can require it before a credential is revealed.
Day-to-day
What your team gets
Vaults with three roles
Group credentials by system, client, or team. Each member of a vault is a reader, a writer, or an admin, and the server and the cryptography enforce the same rule.
Sharing with proof
Sharing encrypts the vault key for one recipient, only after their public key's organisation countersignature has been verified on your device. Signature fails, sharing stops.
Reveal with restraint
Credentials open with fresh authentication, auto-hide after seconds, and clear the clipboard after 30. Rate limits stop a stolen session from reading everything at once.
Search that stays local
Search vault names and entry names instantly. The index is built by decrypting on your machine, once per session, because the server has nothing readable to search.
Password health
Your organisation sets how many months a credential may go unchanged; stale entries are flagged. Every master password is gated by a strength check, not a lecture.
Five languages
English, Tiếng Việt, 日本語, 한국어, 中文, across the entire product, including every warning that protects your data.
Where it runs
Three clients, one implementation of the cryptography
A vault only works if it is open where the password is typed. Keyvaci ships a browser extension and a mobile app for iPhone and Android alongside the web console, and all three are built from the same encryption and the same signature checks rather than from three separate projects that have to be kept in agreement.
Browser extension
Chrome, Edge, and Brave. Click a password field and the menu opens under it, offering only credentials that belong to that site. Keys erase on a ten-minute deadline whether or not you come back, and copies clear from the clipboard after 30 seconds.
iPhone and Android apps
The full vault on the phone, plus a system password provider so Safari, Chrome and other apps can fill from it: iOS AutoFill on iPhone, Android Autofill on Android. Locks the instant you switch away. Biometric unlock is optional and off until you choose it.
Web console
Every browser, nothing to install. Where administrators run members, grants, rotation, recovery, and the audit log, and where Google Workspace sign-in is available today.
One master password opens all three, no client is a paid add-on, and every reveal reaches the same audit log wherever it happened. What each client does, and where each one is today →
For administrators
Control without custody
Administrators run the organisation. They still cannot read a vault they were not given. That distinction is the product.
Countersign new members
Confirm each member's key by comparing a short code over a separate channel, then countersign with the organisation signing key. Impersonation dies at this step.
Recovery you control
When someone forgets their master password, an administrator approves recovery with the organisation recovery key, generated in your browser at signup and never sent to us.
Revoke and rotate
Revoking vault access re-encrypts every entry under a new key, resumable if interrupted. Off-boarding means the old key stops working, mathematically.
Append-only audit
Who opened which vault, revealed which entry, shared and revoked what, and when. The log can be appended to, never edited, not even by us.
Organisation MFA policy
Require a second factor before any credential reveal, for members using email sign-in. Directory members follow the policy you already set in your IdP.
Billing that behaves
Pay for active seats only, prorated. Payment handled by Stripe; card details never touch Keyvaci. Lapsed subscription means read-only, never data loss.
See it with your own tenant
Setup takes minutes either way, and with Microsoft Entra ID it touches nothing else in your directory. Questions about a rollout, another IdP, or a larger team? We answer email quickly.