Vault Send Request How it works Security & Trust Pricing 🇬🇧 🇩🇪 🇫🇷
  • Send
  • Request
  • How it works
  • Security & Trust
  • Pricing
  • Zero-knowledge · Open source

    Share API keys and .env secrets across your team, without pasting them into Slack

    Erseni Vault is the EU-hosted zero-knowledge tool for DevOps teams: share server, database and cloud access through self-destructing links, collect client credentials safely, and keep an audit log of who saw what and when. Self-hostable when you need it to be.

    GDPR-compliant Hosted in the EU Zero knowledge
    Get started free Create a request link

    Why passwords in email threads are a liability

    Every project starts the same way: you need access, and the client sends it the fastest way they know.

    The credentials never go away

    Secrets end up everywhere: the AWS key in a Slack thread, the database password on a Confluence page, an SSH login as a voice note, half a .env sent over WhatsApp to the new hire. Every one of those copies lives on long after the ticket is closed, and none of them ever get rotated. Lose a single account or a single backup and your production access, cloud keys and customer data are all exposed. For a team that sells security, that is precisely the incident you cannot afford.

    How it works

    Three steps, no account needed on the client side.

    Send the request link

    Define which credentials you need (cloud console, CI/CD, container registry, VPN) and send the client a single link. Your browser generates the key pair; the private key never leaves your device.

    The client enters their credentials

    The client opens the link and fills in the fields. Everything is encrypted in their browser against your public key before it is sent. The server only ever sees ciphertext.

    Collect once, link is dead

    You retrieve the credentials a single time and decrypt them locally. Afterwards the payload is deleted on the server and the link is dead. Nothing is left in an inbox.

    How it works

    Built so we cannot read your clients' data

    Zero knowledge is not a promise here, it is the architecture, and the source code is public.

    Nothing in plaintext on the server

    Encryption and decryption happen in the browser (AES-GCM-256, X25519). We store ciphertext and metadata, never the key, never the plaintext.

    GDPR-compliant by design

    Data minimisation, one-time reads, short retention. Credentials that no longer exist on any server cannot leak in a breach, which makes your processor duties a lot easier.

    Hosted in the EU

    Servers and backups stay inside the European Union. No transfer to third countries, no US cloud provider in the request path.

    Read Security & Trust How the encryption works

    Stop sending client passwords through your inbox

    Set up your agency account in under a minute and send the first request link right away. Your clients do not need an account.

    Free tier, no credit card, no sales call.

    Get started free View all plans
    Security & Trust Solutions Comparisons Pricing Status Source Privacy Policy DPA Imprint security.txt © 2026 Erseni Ltd. Zero-knowledge by design.