Multi-level encryption starts with client-side encryption for vault data, followed by transport and storage encryption.
The complete codebase can be audited publicly. Security comes from proper encryption, not from hiding security flaws.
A self-hosted credential manager lets you run the server yourself and gives you greater control over access. It also eliminates the need to rely on public services for your data.
before the data leaves your device
of the server's key
with TLS 1.2 and Salsa20
of all login forms
of all sensitive information
is handled automatically
across all devices
securely between users
for websites and applications
generates random passwords similar to those from our online password generator
to audit your passwords, age, complexity and length
to store other information
for quick access to useful links
captures existing passwords automatically
for all stored secrets
also supports use with desktop applications
for Chrome passwords and other password managers
of users and shares for RBAC
Restricts permissions on shared items.
encrypts and decrypts PGP messages
encrypts and decrypts Gmail, Outlook.com, and Yahoo Mail messages
access your passwords even offline
allow the integration of passwords in build pipelines or startup scripts.
sends callbacks to specific URLs when a secret changes, triggering automated actions such as restarting a service
helps manage digital assets in an emergency or after a death
Old versions of secrets (e.g. passwords) are stored and are accessible in the history
Psono is available in many languages.
with client-side file encryption
All components can be configured for high availability
Scriptable integration of secrets into your infrastructure
IP-based routing enables site-affine storage access, remote-office deployments, and hybrid-cloud setups
Share secrets and files via link with others, even if they don't have an account
Supports local storage, GCP, AWS, and Azure for client-side-encrypted files
Detects if a password has been part of a known breach
Authenticate against your company's LDAP Server, SAML or OIDC IDP. Change passwords, manage email addresses and deactivate users in a central place.
Are compliance and auditing capabilities among your company’s security priorities? This feature lets you trace every REST call.
Enforce rules for your users, such as requiring two-factor authentication or disabling features such as exports, emergency codes, and recovery codes.
Launch browser-based SSH, RDP, and VNC sessions directly from connection entries. Control access with Gateway clusters while credentials remain encrypted during the one-time launch handoff.