DETAIL D4 · ENCRYPTED CREDENTIAL MANAGEMENT

CryptKeepr

Credentials your team can use — and nobody else can read

Passwords, SSH keys, API tokens, and SNMP strings in end-to-end encrypted vaults. The master key never leaves your browser; we could not read your secrets if we tried.

TABLE — CAPABILITIES

What CryptKeepr does

Zero-knowledge vaults

Vault contents are encrypted and decrypted in your browser with a master key derived via PBKDF2 (600k iterations). The server only ever stores ciphertext.

Every credential type

Passwords, SSH keys, API tokens, SNMP community strings, and TOTP secrets — with rotating one-time codes generated in place.

Breach checking, privately

Passwords are checked against known breaches using k-anonymity — only a 5-character hash prefix ever leaves your machine.

Linked to assets

Attach credentials to the devices and assets they unlock. The switch on the map, its record, its runbook, and its login — connected.

Rotation reminders

Set expiry dates and get notified before credentials go stale or shared secrets outlive the person who set them.

AES-256-GCM throughout

Authenticated encryption end to end, TLS 1.3 in transit, and strict per-user isolation — the same posture documented on our security page.

SEE ALSO

The rest of the platform