https://abhibagul.github.io/filepilot/enterprise.html
FilePilot Enterprise Vault is a free, open-source, self-hosted credential server for teams that need shared access to FTP, SFTP, FTPS, SCP, S3, and WebDAV servers — without passing around passwords. Admins provision encrypted connection profiles once, then issue scoped, revocable access tokens to teammates instead of raw credentials.
Credentials are protected with two-tier AES-256-GCM envelope encryption, organized into isolated Vault Groups, each with its own encryption key, IP allowlist, and choice of KMS provider (AWS, Azure, GCP, or HashiCorp Vault). Role-based access control with 20+ granular permissions ensures every action is enforced server-side.
Built for compliance-driven teams, the Vault keeps a tamper-evident, hash-chained audit trail, streams events to your SIEM via signed webhooks, and supports legal holds to freeze data during investigations. A compliance dashboard summarizes encryption, access, and audit postu
Features
- Centralized, encrypted connection profile management (FTP/SFTP/FTPS/SCP/S3/WebDAV)
- Two-tier AES-256-GCM envelope encryption with rotatable master key
- Isolated Vault Groups with per-group encryption keys and IP allowlisting
- Multi-KMS support (AWS KMS, Azure Key Vault, GCP Cloud KMS)
- Role-based access control (Admin, Manager, Operator, Auditor) with 20+ granular permissions
- Scoped, SHA-256 hashed, expirable access tokens with instant revocation
- Tamper-evident hash-chain audit log with integrity verification
- SIEM webhook integration with HMAC-signed payloads and retry-with-backoff
- Legal hold and write-freeze for compliance investigations
- Automatic file version history with one-click remote revert
- Real-time WebSocket sync for tokens, holds, and file reverts
- Two-factor admin login (TOTP) with backup codes and session management
- Compliance posture dashboard (encryption, access, audit, IP policy, sessions)
- Supports SQLite, PostgreSQL, and MySQL
- Self-hosted, MIT licensed, zero telemetry, no per-seat cost