Skip to main content
DigitalSanctum.
← Explore the Sanctum stack

Sanctum Vault / Credential management

Sanctum Vault

Organise credentials and secrets used by infrastructure, applications and service accounts.

Internal tool · adaptable for client work

Credentials with context
  1. Store
  2. Organise
  3. Access
Concept illustration. Not a live application or screenshot.
  • Encrypted credential storage
  • API key and secret management
  • Service account provisioning

How it fits your work

Capabilities in context.

01

Encrypted Storage

All secrets are encrypted at rest using AES-256-GCM with application-layer key derivation. Neither the storage layer nor the filesystem can read plaintext without authorisation.

  • AES-256-GCM encryption at rest with unique per-secret keys
  • Key derivation via Argon2id from master passphrase
  • Encrypted backups with separate backup keys
  • Tamper-evident audit log of all secret access
02

API Key Management

Provision, rotate, and revoke API keys and service account credentials with a single interface. Auto-generate cryptographically random tokens with scoped permissions.

  • Cryptographically random key generation (256-bit)
  • Per-key permission scoping and expiry dates
  • One-click rotation with zero-downtime propagation
  • Usage logging and anomaly detection
03

Access Control

Fine-grained role-based access control governs who can read, write, rotate, or delete each secret. Integrates with existing OIDC providers for seamless authentication.

  • Role-based access control (admin, operator, read-only)
  • OIDC and SAML SSO integration
  • Per-secret and per-folder permission inheritance
  • Granular audit trail with user attribution
04

Zero Third-Party Dependency

The entire vault runs on your own metal — no external secret management APIs, no cloud KMS, no SaaS backends. If your network is up, your vault is accessible.

  • Self-contained deployment with no external API calls
  • No dependency on AWS KMS, HashiCorp Cloud, or 1Password
  • SQLite-backed storage for zero infrastructure overhead
  • Full air-gap deployment capability

Start with a real use case

What should Sanctum Vault make easier?

Tell us about the work, the people involved and the result you need. We’ll agree the capabilities and implementation scope together.

Already have access? Sign in to Sanctum Vault ↗

Digital Sanctum knowledge base

Search Digital Sanctum

Find services, processes, products, case studies, and strategic intelligence. Search stays in your browser.

Type at least two characters to search the knowledge base.