Divan Talk to us

Vault : Credentials that are used, never shown.

The credentials the organisation keeps: saved once, used without being seen, given for a time. The Vault hands a secret out as work done - a session opened, a request signed - and never as text on a screen.

Illustrative

What it does

Vault, point by point.

01

Saved once, write-only

A secret goes straight from the browser to the keeper, or the keeper makes it. After that there is no screen, and no door in the keeper, that returns it.

02

Safes with four levels

In a safe a person sees, uses, manages or owns. Seeing that a credential exists is not being able to use it.

03

Access with an end

A grant has a last day. People ask for access; whoever answers for the safe approves it from their cartable.

04

Sessions inside the platform

RDP and SSH open in the browser, already signed in. The person never learns the password. A session can be watched live, ended, and replayed afterwards.

05

A browser that is already signed in

Web systems open in a contained browser that the Vault signed in. An agent may drive it for the organisation - on a portal, on a supplier's site - without holding the login.

06

Bound to where it belongs

A credential is tied to the system it is for. Used in a web request, it goes only there, and its value is scrubbed from what comes back.

07

Rotation

Passwords and keys of servers are changed by the Vault itself, so the value in use is one nobody ever saw.

08

A record of every use

Who used what, when, for what - and one switch that stops every use at once.

See it work

Try to see the password

Two buttons. One of them is the whole idea of the Vault.

Servers safe

Demo
web-01 root, over SSH
Yours to use until 18:00
••••••••••••••••

A credential in the Vault can be used. It cannot be read - by anyone.

  1. Rotated by the Vault, 2 days ago
  2. Saved by Omid, write-only, 3 weeks ago

Getting started

Three steps in.

  1. Open Vault and make a safe for your team.
  2. Add an item: type the secret once, or let the Vault make one.
  3. Give people use of it, with an end date.

The tasks people do with Vault, step by step

Questions

What people ask about Vault.

Can an administrator read a password?

No. Nobody reads a value back - not the person who saved it, and not an administrator. It can be used, replaced, or rotated.

Where are the values kept?

In a dedicated secret store on a network of its own, behind a keeper that only acts on one-use tickets the platform signs.

How do agents use credentials?

Like people: by grant, for a time, for a purpose - and without ever reading the value.

See Divan on your own servers.

Tell us about your organisation and what you want to run. We will show you the platform on the work you actually do.