Zero-knowledge vault
AES-256-GCM encryption happens in the browser with an Argon2id-derived key. The server stores an encrypted envelope instead of plaintext secrets.
ZERO-KNOWLEDGE PASSWORD MANAGER FOR ORGANIZATIONS
Vault18 stores, shares, and autofills passwords, API keys, MFA codes, secure notes, and encrypted attachments in an organization-isolated vault.
ONE ORGANIZATION VAULT
AES-256-GCM encryption happens in the browser with an Argon2id-derived key. The server stores an encrypted envelope instead of plaintext secrets.
Invite organization members and assign only the records they need with one-time, read-only, edit, create, read-write, or admin access.
Use Vault18 extensions for Chromium browsers, Firefox, and Safari conversion. Credentials are offered only for an exact website-origin match.
Generate saved TOTP codes and create a user-held recovery kit. Vault18 does not escrow the master password or plaintext recovery key.
Protect service tokens, API keys, secure notes, and encrypted files alongside website logins in the same organized workspace.
Manage members, audit activity, custom branding, custom domains, backups, and record-level permissions within each isolated organization.
COMMON QUESTIONS
Vault18 is an invitation-only password manager and secrets vault for organizations. It protects passwords, API keys, MFA secrets, secure notes, and attachments.
No. Vault data is encrypted in the browser before upload. The master password and plaintext vault are not sent to the server.
Yes. Administrators assign individual records with granular roles, and the extension autofills only when the saved and current website origins match exactly.