DETAIL D4 · ENCRYPTED CREDENTIAL MANAGEMENT
Credentials your team can use — and nobody else can read
Passwords, SSH keys, API tokens, and SNMP strings in end-to-end encrypted vaults. The master key never leaves your browser; we could not read your secrets if we tried.
WHO THIS IS FOR
For teams whose device passwords currently live in a shared spreadsheet named "DO NOT SHARE.xlsx".
PART OF THE PLATFORM
CryptKeepr is one of four tools under a single Layer8 Systems account — switch between them without a second login.
What CryptKeepr does
Vault contents are encrypted and decrypted in your browser with a master key derived via PBKDF2 (600k iterations). The server only ever stores ciphertext.
Passwords, SSH keys, API tokens, SNMP community strings, and TOTP secrets — with rotating one-time codes generated in place.
Passwords are checked against known breaches using k-anonymity — only a 5-character hash prefix ever leaves your machine.
Attach credentials to the devices and assets they unlock. The switch on the map, its record, its runbook, and its login — connected.
Set expiry dates and get notified before credentials go stale or shared secrets outlive the person who set them.
Authenticated encryption end to end, TLS 1.3 in transit, and strict per-user isolation — the same posture documented on our security page.