Vault
A real secrets engine — encryption at rest and in transit, fine-grained policies, PKI, and a full audit trail — priced flat per organisation, not per person or per machine identity.
7 days free, no card required.
Noviqent Vault is a centralised secrets store for API keys, database credentials, and certificates, built so a product never has to keep its own second, encrypted copy sitting in a database somewhere. A product authenticates with a scoped AppRole identity and asks for exactly the secret its own policy allows — nothing else in the vault is reachable with that credential, and every read, write, and policy change is logged against the identity that made it.
Beyond plain storage, Vault issues and revokes X.509 certificates on demand (PKI) for services that need mutual TLS without a manually-managed certificate lifecycle, and supports dynamic, short-lived credentials that auto-revoke on a lease for integrations that support it. Two-factor authentication (TOTP) protects every login, and unseal keys are Shamir-split so no single person — including whoever operates the host — can unseal the vault alone.
Vault is what every other Noviqent product (Business Operations Platform, Accountancy, Cloud & Kubernetes Compliance, and more) uses under the hood to store each customer's own connected-service credentials, and it's also available entirely standalone — a real secrets engine for your own products, not a bolted-on password manager.
Features
- Encryption at rest and in transit — every secret encrypted before it touches disk, every connection TLS
- Fine-grained, path-scoped access policies — a product or person gets exactly the secrets they need, enforced by the vault itself
- Full audit trail — every read, write, and policy change logged against the identity that made it, never anonymous
- PKI — issue, sign, and revoke X.509 certificates on demand, without a manually-managed certificate lifecycle
- Dynamic secrets — short-lived, auto-revoking credentials for integrations that support it, beyond static values
- Versioned secret storage — recover a previous version of a secret, not just the current one
- Two-factor authentication (TOTP) on every login, and Shamir-sealed unseal keys so no single person can unseal the vault alone
- Identity Brokering-ready — bring your own IdP (Okta, Azure AD, your own Keycloak), scoped to just your own users
- Dedicated single-tenant and self-hosted deployment tiers for organisations that need their own isolated instance
Pricing
Free Developer tier (3 users, 50 secrets), Starter from £15/mo, Business from £39/mo, Enterprise from £149/mo — plus dedicated single-tenant and self-hosted tiers from £99/mo.