...Admins provision encrypted connection profiles once, then issue scoped, revocable access tokens to teammates instead of raw credentials.
Credentials are protected with two-tier AES-256-GCM envelope encryption, organized into isolated Vault Groups, each with its own encryption key, IP allowlist, and choice of KMS provider (AWS, Azure, GCP, or HashiCorp Vault). Role-based access control with 20+ granular permissions ensures every action is enforced server-side.
Built for compliance-driven teams, the Vault keeps a tamper-evident, hash-chained audit trail, streams events to your SIEM via signed webhooks, and supports legal holds to freeze data during investigations. ...