Marrinn Vault.
Every team has a spreadsheet of passwords, a shared inbox with an API key in it, and one person who knows the production credentials. Vault ends all three — encrypted end to end, shared properly, and logged completely.
Your secrets are already leaking. Quietly.
Not through a dramatic breach — through the ordinary business of getting work done. A key pasted into a chat, a password reused across four systems, a contractor who left in March and whose access nobody revoked.
✕Credentials in chat
Once a key is in a message thread it is in search results, backups and exports — permanently.
✕The shared spreadsheet
Convenient, unencrypted, unversioned, and copied to three laptops the moment it is useful.
✕Nobody rotates anything
Rotation is a manual chore, so it never happens — and old credentials stay valid for years.
✕Leavers keep access
Offboarding revokes the SSO account but not the twelve passwords they memorised or saved.
✕No idea who opened what
When something does go wrong, there is no log to tell you the blast radius.
✕Consumer tools, business risk
A browser password manager was not designed for shared production infrastructure.
Encrypted before it leaves the device.
Vault is zero-knowledge by design. Secrets are encrypted in the browser or the app with a key derived from your master passphrase, and the server only ever stores ciphertext. If someone walked out with the entire database, they would have nothing readable.
The server holds ciphertext. That is all it holds.
Client-side encryption, per-vault keys, and a sharing model that hands out keys to people rather than copies of passwords to inboxes.
- Client-side encryption — plaintext never crosses the network
- Per-vault keys wrapped to each member's public key
- Revocation actually revokes — remove access, re-wrap the vault
- Break-glass recovery for when the person with the passphrase is unavailable
- SSO and two-factor on top, not instead of, the encryption
- Production database — root••••••••••••
- Stripe live secret key••••••••••••
- TLS certificate — wildcard••••••••••••
- SMTP relay credentials••••••••••••
- Cloud provider API token••••••••••••
5 secrets · shared with Platform team (4 members) · last opened 2 hours ago
Everything a team needs, nothing a team will not use.
Adoption is the whole game with a password manager. Vault is built so that the secure path is also the quick path — otherwise people go back to the spreadsheet.
Every secret type
Passwords, API keys, SSH keys, certificates, database strings, secure notes and files.
Team vaults
Organise by team, project or environment. Membership drives access — no manual re-sharing.
Role-based permissions
View, use, edit or manage. Grant time-boxed access that expires on its own.
Rotation & versioning
Rotation reminders, full version history, and one-click rollback when a change breaks something.
Complete access log
Every read, edit, share and export recorded — exportable for your auditors.
SSO & two-factor
SAML and OIDC single sign-on, enforced 2FA, and offboarding that revokes everything at once.
Where your people are
Browser extension, desktop and mobile apps, and a CLI for pipelines and servers.
Cloud or on-premise
Run it on your own infrastructure via Docker, or let us host it. Same product either way.
An assistant that watches the vault, not the contents.
The AI layer works on metadata — access patterns, ages, sharing shape, breach feeds — never on your plaintext secrets, which it cannot read either.
Risk review
Ranks the secrets most worth attention: over-shared, never rotated, or reused across systems.
Dormant access
Flags members who hold access to vaults they have not opened in months, ready to revoke.
Breach matching
Checks stored credentials against known breach corpora and tells you what to rotate first.
Sharing advisor
Spots secrets shared with the whole company that should sit with one team.
Rotation planner
Proposes a rotation order that minimises the risk of taking production down.
Log narrator
Turns the raw access log into a plain-English summary for your monthly security review.
Your secrets, in your jurisdiction.
A password manager is only as trustworthy as the company holding it and the country it sits in. Vault is built by a UK company, and you decide where it runs.
Self-hosted via Docker
Run the whole thing inside your own network. No outbound dependency on us to unlock your own credentials.
Or hosted by us
If you would rather not run it, we will — in the region you choose, written into your contract.
Zero-knowledge either way
Hosted or self-hosted, the encryption model is identical. We cannot read your vault in either case.
Get the passwords out of the spreadsheet.
We will walk you through Vault on your own structure — teams, environments and the credentials you are most nervous about.
