CW-P / Secrets & credential manager

Vault

Secrets that never touch the ground.

CW·01 / System brief

Product intent · artifact not released

Secrets & credential manager

Encrypted secrets, tokens and certificates synced to every environment, sealed by hardware-backed keys.

Coming soon. This product is awaiting a verified release artifact. Purchase, activation, and download are intentionally unavailable.
AvailabilityComing soon

Planned access

All feature groups are intended to be included with each pass.

View planned pricing
CW·02 / Planned capability map

7 intended feature groups

End-to-end encryptionPlanned

XChaCha20-Poly1305 at rest, TLS 1.3 in transit, and keys sealed in TPM 2.0 or Secure Enclave. Plaintext exists only in the process that asked for it.

Environment syncPlanned

One sealed value follows your code from laptop to CI to production. Offline edits merge deterministically on reconnect.

Access policiesPlanned

Grant read or write per secret, scoped by environment, role or machine. Deny by default—every grant is explicit.

Rotation schedulesPlanned

Rotate on a calendar, not after an incident. Overlap windows keep old values valid while deploys catch up.

Leak detectionPlanned

Salted fingerprints of your secrets are matched against staged commits before each push. A hit blocks the push and names the line.

CLI + SDKPlanned

vault run injects secrets as environment variables that die with the process. SDKs for eight languages; nothing is written to disk.

Audit trailPlanned

Every read, write and rotation is signed and append-only. Export as JSON or give auditors a scoped view.

CW·03 / Pass matrix

USD · one-time planned prices

1 Day
$4.99
$4.99/day
7 Days
$14.99
$2.14/day · Save 57%
30 DaysPopular
$29.99
$1.00/day · Save 80%