centilio
Centilio

Explore the products

A business OS.
Room to grow.

Start with one tool. Explore the wider suite as your needs grow.

Explore Centilio One ↗Product availability follows the catalogue.
CENTILIO VAULT / TRUST

The right access.
In the right hands.

Your team’s password manager. Bring credentials into one organised place, make sharing deliberate and keep access in view.

Private by designShared with intentionReviewed by people
VAULT
PERSONAL COLLECTION

A place for every credential.

Studio loginLogin · private
Service credentialKey · private
Recovery noteNote · private

Illustrative workspace · no real credentials

THE PRIVACY PRINCIPLE

Keep the secret.
Protect the handover.

Explore the intended boundary in three steps. This is an explanatory model, not a live encryption trace.

DEVICE / PRIVATE CONTEXT

Your authorised device

Credential content stays inside the intended protection boundary.

SERVICE / PROTECTED RECORD

Nothing to transfer yet.

Start with the device and session you trust. This diagram contains no real password.

Security is implementation-specific. Read the published architecture and findings ↗

A USEFUL START

Make the next password
a better one.

Choose the length and character groups. Generate a fresh password here, on your device.

GENERATED ON THIS DEVICE

No account connection. Nothing is submitted.

No saving or sending. If copied, the password stays on your clipboard until you replace it; this page cannot clear clipboard history.

Include at least one from each selected group

Adjust this example to a service’s requirements. This is a standalone utility, not your organisation’s enforced Vault policy.

SHARING WITH INTENTION

Give access a purpose.
And an owner.

Walk through a team handover. The useful question is who needs access, to what, and for how long.

A CLOSER LOOK / NEW TEAMMATE

Start with the role.

A new person does not need every credential. Begin with the work they are responsible for.

What this example means

Roles shown here are planning examples. Confirm the actual permissions in your Vault deployment.

VAULT / ILLUSTRATIVE BRIEF
01

PersonNew design teammate

02

CollectionDesign tools

03

ReviewConfirm the appropriate role

Sample context only. No account action is performed.

CELIA / THE INTENDED BOUNDARY

Context for Celia.
Control for your people.

A concept for useful assistance: approved metadata informs a draft, and a person decides what happens next.

01 / PERMITTED CONTEXT

The shape of the work.

Role: designer · Collection: design tools

CeliaCONTEXT → DRAFT
02 / PREPARED FOR REVIEW

Prepare an access checklist for the design collection.

A person confirms the role and the specific items before granting access.

Where did this come from?

Prewritten example using the sample metadata shown here. No model, secret store or account is connected.

Illustrative concept, not a release claim. Never place passwords, recovery keys or confidential secret values in an AI prompt. Explore Celia’s role ↗

CAPABILITIES / BY TASK

Find what matters.
Leave the long list behind.

Start with the job you need to do. Open a capability for the detail to check with your team.

8 capabilities

DAILY

Vault items

Logins, notes and other credential records.

What to check
Choose a clear naming and collection convention before importing.
DAILY

Password generation

Length, character groups and exclusions.

What to check
Use a unique password for each service and check its requirements.
DAILY

Browser extension

A shorter path from a login page to its credential.

What to check
Confirm the supported browser and the correct Vault domain.
TEAM

Role-based sharing

Access scoped to the people who need it.

What to check
Review the exact permissions of each role before sharing.
TEAM

Activity and audit

Context for reviewing access and account activity.

What to check
Confirm event coverage, retention and export options.
ADMIN

Multi-factor authentication

An additional check at sign-in.

What to check
Test enrolment and your organisation’s recovery process.
ADMIN

Recovery preparation

A plan for losing access to a device or factor.

What to check
Keep recovery material private and follow the documented procedure.
ADMIN

Import and export

A route into Vault—and a route out.

What to check
Test a small non-sensitive sample before moving real credentials.

Selected public feature highlights—not a guarantee for every deployment. Read the published catalogue ↗

THE EVERYDAY EXPERIENCE

One Vault.
Different moments.

Organise at your desk. Find a login in the browser. Keep unlock decisions on the right device.

VAULT / WEB APP CONCEPT
MY WORKSPACEDesign collection

Studio login ••••••

Project note ••••••

Service key ••••••

LISTED IN THE PUBLIC CATALOGUE

The place to organise.

A central workspace for items, collections and team settings.

Native mobile apps are listed as roadmap. These views do not connect to an account or invoke biometrics.

Check current compatibility ↗
FOR THE SECURITY BUYER

Trust deserves evidence.
Not just a label.

A focused review to take to your security team. Open each topic for the questions behind the decision.

01 / IMPLEMENTATION

What is running in this deployment?

Ask for the deployed version, key-handling design and current derivation settings. The published security page describes both a target algorithm and a migration state; confirm the implementation rather than relying on a headline.

02 / ACCESS AND RECOVERY

Who can regain or change access?

Review role permissions, MFA enrolment, session revocation and recovery procedures. Test the intended path with a non-sensitive account.

03 / INDEPENDENT EVIDENCE

What has actually been assessed?

Request the latest assessment date, scope, unresolved findings and remediation status. Public source or a security description is not an independent audit.

04 / OPERATIONS

Who owns the operational work?

Agree hosting, backups, restore testing, retention and incident responsibilities. Self-hosting changes the owner of that work; it does not remove it.

HOSTING / YOUR CHOICE

Choose who runs it.
Know what it costs.

Three starting points, with the operational responsibilities made visible.

SELF-HOSTED

Free

software licence

Your infrastructure. Your operations.

What to plan for

Plan for hosting, patching, monitoring, backups and restore tests. Request the current source and deployment documentation.

TEAM

$5

USD / user / month (in dollars)

Hosted by Centilio. Scoped to your team.

What to plan for

Confirm account eligibility, included support, backup arrangements, retention and billing terms before purchasing.

ENTERPRISE

Custom

contract and deployment

Start with your organisation’s requirements.

What to plan for

Discuss identity, hosting, residency, audit and support requirements. Confirm each commitment in the agreed contract.

TEAM / COST ESTIMATE

A number you can work with.

ESTIMATED TOTAL / USD (in dollars)$50.00

For 10 users per month, before taxes.

Annual estimates use the published 10% discount. Confirm the actual invoice, currency and terms with Centilio. This is not a checkout.

USD pricing checked 6 September 2026. Infrastructure costs are not included in self-hosted software pricing. Verify current plans and terms ↗

A PRACTICAL FIRST STEP

Try a small pilot.
Learn the right things.

A useful evaluation is a complete path, not a promise about setup speed.

01 / PILOT REVIEW

Start with a sample

Use fictional credentials and a small test collection.

02 / PILOT REVIEW

Walk through access

Check the intended roles, sharing and sign-in experience.

03 / PILOT REVIEW

Test the recovery plan

Review recovery, export and restore procedures with the owner.

04 / PILOT REVIEW

Agree the rollout

Confirm responsibilities, current terms and the migration plan.

0 of 4 reviewed

Personal checklist only. It resets on reload and does not certify security, submit approval or change an account.

QUESTIONS / ANSWERED

A little more clarity.
A more informed choice.

From hosting and recovery to the boundaries of the examples on this page.

9 answers

Ask the Vault team ↗
What is Centilio Vault for?

Vault is a business password manager for organising credentials, sharing access within a team and reviewing account activity. Use the public product catalogue and a pilot to confirm the capabilities available in your deployment.

What does zero-knowledge mean in Vault’s design?

The intended design keeps plaintext credentials and usable encryption keys on the authorised client while the service stores protected records. Confirm the deployed implementation, key handling and recovery model; the phrase is not a guarantee against every attack.

Is this page connected to my real vault?

No. The workspace, device and Celia examples are illustrations. They do not access credentials, change permissions, invite people or invoke biometric verification.

Does the generator save or send passwords?

The generator uses your browser’s secure random source and does not submit or save the result. Reloading clears it from the page. Copying places it on your clipboard, which may retain it or sync under your device settings until you replace it.

How much does Vault cost?

The published pricing lists self-hosted software as free, Team at USD 5 per user per month and Enterprise as custom. Infrastructure and operations are additional for self-hosting. Yearly examples here estimate the published 10% discount; confirm taxes and current terms before purchasing.

Is Celia reading my passwords here?

No. The Celia fold uses prewritten examples and sample metadata, not a live model. Never put password values or recovery keys into an AI prompt. Actual product capabilities and data boundaries must be confirmed for your deployment.

Can I move from another password manager?

The public catalogue lists import and export capabilities. Confirm the supported formats and test a small non-sensitive sample first. Keep source exports private and verify the result before changing your existing service.

Which apps and devices are supported?

The public catalogue lists a web app, a Chrome extension and a desktop companion. Native mobile apps are marked roadmap. Confirm current browser, operating-system, hardware and deployment requirements.

What should I do about recovery?

Review the documented recovery process before storing real credentials. Keep recovery material private, test the approved procedure with your administrator and do not paste recovery keys into this page or a support conversation.

VAULT / IN YOUR HANDS

A clearer way
to move forward.

Start a conversation, review the evidence or explore the wider Centilio system.

YOUR NEXT STEP

Start with your team.

Discuss the deployment, the people and the requirements that matter to your organisation.

Discuss Vault ↗