ReleaseMONITIC 2026.07 — Synapse Control Plane is live: topology, blast radius & AI-driven RCASee what's new
Feature

A password vault for IT teams — sealed per tenant, audited per reveal

Most team password managers were designed for individuals and stretched to fit organizations. Monitic's vault was designed for IT operations from the start: credentials organized by folder, every entry's payload individually encrypted, and every reveal written to an audit trail with the actor's name on it. It lives inside the privileged access module of the Monitic platform, so vault access follows the same roles and company scoping as everything else your team does — no separate user list, no separate audit silo.

Envelope encryption: what a database dump gets an attacker

Nothing. Each vault entry's payload is sealed with AES-256-GCM under a data key unique to your tenant. That data key is itself wrapped by a master key held apart from the database. An attacker holding a full dump of the datastore holds ciphertext — without the master key there is no path back to plaintext, for any tenant. This is envelope encryption as practiced by cloud key-management services, applied per entry and per tenant.

Two properties follow. Tenant isolation is cryptographic, not merely logical: one tenant's key material never decrypts another tenant's entries. And the blast radius is bounded by design: keys are layered so that no single stored artifact yields the secrets.

Every reveal is an audit event

A vault is only as trustworthy as its answer to "who saw this password, and when." In Monitic, revealing a credential is always audited — actor, entry, timestamp. There is no quiet read path to a secret. Updates are audited too, with a distinction auditors appreciate: partial-update flags record whether a change touched the secret payload or only metadata such as the title or folder. A renamed entry and a changed password are different events, and the log says so without anyone reading diffs.

Built for how IT teams actually share credentials

Folders map to how your operation is structured — by client, by site, by system class. Access follows the platform's role-based access control: granular permissions decide who can read and who can manage, and per-company allow-lists keep MSP technicians inside their assigned clients. Because the vault shares its identity layer with the rest of Monitic, a new technician provisioned through SCIM lands with correctly scoped vault access on day one — and loses it the day the IdP says so.

Works with

The vault is one half of the privileged access story. Privileged assets & sessions attaches credentials to servers and network devices and brokers sessions to them, so technicians get access without holding standing secrets. Identity & directory governs the roles and provisioning that decide who can open which folder. Both roll up to the privileged access hub, included in the Enterprise tier — see pricing.

Put your credentials somewhere defensible

A vault your auditors can verify and your technicians will actually use — inside the console they already work in. Start free trial — 14 days, full-featured — or get a demo. Back to privileged access.

FAQ

Frequently asked questions

How is the vault encrypted?

Per entry, with AES-256-GCM, under a per-tenant data key wrapped by a separately held master key — envelope encryption. A database dump without the master key yields only ciphertext.

Can we tell who viewed a credential?

Yes, always. Every reveal is an audit event carrying the actor, the entry, and the timestamp. There is no unaudited way to read a secret out of the vault.

Can we tell whether an update changed the actual password?

Yes. Partial updates carry audit flags distinguishing metadata edits from secret changes, so an auditor can separate a folder move from a password change at a glance.

Is the vault a separate product?

No. It ships inside the privileged access module in Monitic's Enterprise tier — on a platform with per-endpoint plans.

Ready when you are

See Monitic on your own fleet

Full-featured 14-day trial · no credit card · your real fleet in the console on day one.