Vault by Empyre

Vault terms of service

These terms govern Vault accounts, organizations, agents, policies, stored secrets, temporary credentials and signing operations. They cover account responsibility, acceptable use, subscriptions, card payments, availability, suspension, intellectual property and limits of liability.

You are responsible for the data and credentials placed in Vault, the policies that grant access, the agents you authenticate and the legality of each operation. Vault must not be used to conceal unauthorized access, sign deceptive material, bypass provider restrictions or handle another person's credentials without authority.

How Vault works

Vault stores the credentials AI agents need and signs with private keys that must never leave controlled storage. Policies are deny by default: an operation needs a matching allow and no matching deny, and every access decision is written to an audit trail.

Agents can receive short-lived temporary credentials with expiration and read limits, while signing keys have no read path at all. The agent sends a payload and receives a signature, never the private key. Organizations can rotate secrets, revoke credentials, monitor usage and investigate security alerts from one account.

Public pages

JavaScript is required to sign in and use the Vault dashboard. The product information above and the linked public pages remain readable without it.