Log inGet Vautir

Search the help center, features, guides and more.

Security review answers

Answers to the questions a vendor security review asks about Vautir, section by section.

Security teams ask vendors much the same questions, whatever the questionnaire: CAIQ, SIG Lite, or their own. These are Vautir’s answers, kept current on this page.

Product and data

Question Answer
What does the service store? Each account’s email address, public keys, a login record nothing can be guessed from, keys it can’t open, and encrypted vaults, items and files. For a shared vault, who shares it with whom, and in which role. For an organization, its signed roster, its audit log, and what its identity provider sent through SCIM.
Can Vautir read our vaults? No. Items are encrypted on each person’s device with keys the server never has. Titles, website addresses, tags, notes, files and device names are encrypted too.
What can Vautir see? Email addresses, when devices sync, how many items a vault holds and their padded sizes, who shares a vault with whom, and each plan and when it renews, never a card. For an organization: its name, its members and their roles, who has which vault, its policies, and the group names an identity provider sends. Group names made in the console, and every vault’s and item’s name, are encrypted.
Is our data used for analytics, advertising or training models? No. The apps contain no third-party trackers, and vault data can’t be read to begin with.
Where is data stored? In separate regions in the United States and the European Union. Each account stays in the region chosen at sign-up, backups included.
Can we host it ourselves? The server runs on your own machines, with organizations, single sign-on, SCIM and audit logs included. See Self-hosting.
How do we get our data out? Every person can export their vault at any time, on every plan: as Vautir JSON, as a Credential Exchange file, or as CSV.

Encryption and keys

Question Answer
How is vault data encrypted? On each person’s device, with modern authenticated encryption, under a random key for each item. Each item is bound to its place, so it can’t be swapped or moved, and content is padded so sizes reveal little.
How are keys derived? From the master password, stretched so each guess is slow and costly, and a 128-bit Secret Key that only the person’s devices hold.
Who holds the keys? Only each person’s devices. The server stores keys only wrapped by keys it doesn’t have.
How is data protected in transit? With TLS. The apps refuse plain http except to a server on the same computer, and the native apps check the server’s certificate with the operating system’s own verifier. Each request is also signed by the device that sends it.
How are shared vaults protected? Each vault key is sealed to each member with post-quantum encryption. Member lists are signed by the vault’s owner.
Is there post-quantum protection? For shared vault keys, yes. Symmetric encryption uses 256-bit keys throughout.
Are the formats documented? Yes, in a full specification with test vectors, which a second, independent implementation checks on every change. The firms that review Vautir get both, under confidentiality.

Signing in and access

Question Answer
How do people sign in? With a password-authenticated key exchange. The master password never reaches the server, and the server stores nothing a breach could crack. A new device also needs the account’s Secret Key.
Is there multi-factor authentication? The Secret Key is a second secret that only the person’s devices hold, so a phished master password alone can’t sign in. With single sign-on, your identity provider’s second factors apply before a new device gets in.
Single sign-on? Yes, for OpenID Connect and SAML 2.0, in Teams and Business. The identity provider vouches for a person before their new device gets a session, and never holds a key: keys still come from the master password and Secret Key, or from a key connector the company runs on its own servers. Owners sign in without it, as a way back in. It’s the server’s check: a hostile server could skip it, and still couldn’t read a vault. See Single sign-on.
Provisioning with SCIM? Yes, to SCIM 2.0, in Business. The server can’t add anyone by itself: an admin’s device signs each addition, after checking the person’s key against the key transparency log. Deactivating someone takes the organization’s vaults from them at once. See SCIM.
What roles are there? In an organization: owners, admins and members, with vaults granted to groups or to people, to edit, to view, or only to fill. The roster is signed with the organization’s own key and checked by every member’s device, so the server can’t change it. A vault shared between people has an owner, people who can edit and people who can view.
Can admins read everything? Admins can open every vault of the organization. They can’t open a member’s own vaults, unless the organization lets admins approve members’ new devices, which every member’s app then states.
What happens when someone leaves? Every vault they had gets a new key, with each item encrypted again. Offboarding then lists what they could open, and which items still hold what they saw, with a report.
How are sessions handled? Each device has its own key and signs every request. A session lasts 30 days, and ends at once when the device is signed out from another device or the master password changes.
What stops password guessing? Sign-in and recovery are rate-limited, and an unknown account answers like a real one. Guessing against a stolen copy of a vault needs the 128-bit Secret Key as well as the password.
Are there audit logs? Yes. Each organization’s log records sign-ins, changes to members, groups, vaults and policies, admin actions, and items opened or filled, numbered without gaps. Admins read it in the console, and on Business it’s sent on to a webhook, Splunk, Datadog, Microsoft Sentinel or S3. The server writes it, and item opens are reported by the apps, so it’s a record, not a control. See Audit logs.
How do scripts and CI get secrets? Through the command line, with service accounts: an account of its own for a build, which opens only the vaults shared with it, by a token that’s deleted to take everything back. See Developers.

Integrity

Question Answer
Could the server change or roll back a vault? Devices would refuse it. Every write carries a manifest of the vault’s items, signed with the writer’s identity key, and devices reject a vault with missing, rolled-back or swapped items.
Could the server swap someone’s public key? Devices check every key they seal to against a public, append-only key transparency log, watch their own entry in it, and compare what they saw with each other.
Could the server add itself to a shared vault? No. Member lists are signed by the vault’s owner, and every member’s device checks them.

The software

Question Answer
Is the source code available? No. Vautir’s code is proprietary. The firms that audit Vautir review it, and their reports are published in full.
How is it tested? Every change runs the full test suites, end to end against a real server and in Chrome, Edge and Firefox, and an independent check of the encryption.
How are dependencies managed? Every dependency is checked for advisories, licenses and sources. Versions are pinned, and new versions are adopted only after 7 days.
Is there third-party code in the apps at run time? No analytics, trackers or remote scripts.
Are releases signed? Yes. Every release is signed, with build provenance and a software bill of materials.
How are vulnerability reports handled? Under the disclosure policy, with safe harbor for research in good faith.

Operations

Question Answer
Where is it hosted? With the providers on the subprocessors page, in the account’s region.
What availability can we expect? The apps keep the vault on each device and work offline, so an outage pauses sync and sharing but locks nobody out. The hosted service’s targets are 99.95% uptime for sync, at most 5 minutes of data loss, and recovery within 1 hour.
How is data backed up? With point-in-time recovery for the database, kept in the account’s region.
Who at Vautir can reach production? Access is granted for a task and a time, logged, with a second person’s approval. Whatever access staff have, vaults stay unreadable.
What do the server’s logs hold? Errors and events. Never request bodies, and never anything from a vault, which the server couldn’t read anyway.
How are incidents handled? With a runbook, a public status page, notice to affected customers and regulators within 72 hours as the GDPR requires, and published post-mortems.
How do we report a vulnerability? Write to security@vautir.com. We confirm within 2 working days, assess within 7 days, and fix within 90.

Compliance and privacy

Question Answer
Is there a data processing agreement? Yes, the data processing agreement, under Article 28 of the GDPR. Vault data is processed only as ciphertext.
Who are the subprocessors? They’re on the subprocessors page. Business customers get 30 days’ notice before one is added.
What happens when an account is deleted? The server deletes the account with every vault, item, file and session, and the device wipes its own copy.
Does the website track visitors? It sets no tracking cookies, and loads no scripts, fonts or embeds from other sites. The free breach check asks Have I Been Pwned about five characters of a hash, and only when a visitor uses it.

Need a filled-in CAIQ or SIG Lite, or an answer that isn’t here? Write to sales@vautir.com.

Last updated October 5, 2026