Knowledge base · Security & data

Security overview

How credentials and backups are protected: envelope encryption, sealed secrets, audited access, tenant isolation, and what we do not do.

VaultKeep holds keys to production databases, and the product is organised around that fact. This page is the practitioner's summary; the Privacy Policy covers the legal side.

Credentials

Backups

Isolation

Audit log

Append-only, enforced by database triggers, covering sign-ins, credential reads, backups, verifications, restores, plan changes, team changes and destination changes. Exportable as CSV from the app. Retained for 90 days after an organization is deleted.

Platform

VaultKeep runs entirely on Cloudflare (Workers, D1, R2, Containers, Queues, Cron Triggers), with Stripe for payments and Resend or Cloudflare for email. Sessions use one strictly necessary cookie. Optional Turnstile protects sign-in from bots.

What we do not do (yet)

Reporting a vulnerability

Email support@vaultkeep.dev with "Security" in the subject. We acknowledge reports promptly, fix confirmed issues, and credit you if you wish. Please don't test against other customers' data.


Still stuck? Email support@vaultkeep.dev with your project name (never your connection string) and we'll take a look.