Vault by Empyre

Vault privacy policy

Vault processes account and organization details, agent identities, policy configuration, encrypted secret records, signing-key metadata, temporary credential metadata, usage measurements, audit events, security alerts and the information needed to reconcile card payments.

Secret values and private key material are restricted to the operations requested through the service. Signing keys deliberately have no read path. Access controls, encryption, retention and deletion differ by record type so operational evidence can be preserved without exposing the credential it describes.

How Vault works

Vault stores the credentials AI agents need and signs with private keys that must never leave controlled storage. Policies are deny by default: an operation needs a matching allow and no matching deny, and every access decision is written to an audit trail.

Agents can receive short-lived temporary credentials with expiration and read limits, while signing keys have no read path at all. The agent sends a payload and receives a signature, never the private key. Organizations can rotate secrets, revoke credentials, monitor usage and investigate security alerts from one account.

Public pages

JavaScript is required to sign in and use the Vault dashboard. The product information above and the linked public pages remain readable without it.