Credential Vault
AES-256 encrypted secrets, revealed only where you choose.
Encrypted at rest, gated by role
Every credential is stored with AES-256-GCM encryption. Reveal permission is a role, not a favour - technicians can see a credential exists without ever seeing the secret itself, while admin-tier accounts can reveal what they need to do their job.
Every reveal is logged, so there is always an answer to 'who looked at this, and when'.
Import what you already have
Bring an existing KeePass vault across in one import, rather than re-entering every credential by hand.