Your authorised device
Credential content stays inside the intended protection boundary.
Your team’s password manager. Bring credentials into one organised place, make sharing deliberate and keep access in view.
Illustrative workspace · no real credentials
Illustrative workspace · no real credentials
Explore the intended boundary in three steps. This is an explanatory model, not a live encryption trace.
Credential content stays inside the intended protection boundary.
Start with the device and session you trust. This diagram contains no real password.
Credential content stays inside the intended protection boundary.
Vault describes client-side encryption. Verify the current implementation and key handling for your deployment.
Credential content stays inside the intended protection boundary.
An encrypted database is one boundary, not immunity from compromised devices, weak credentials or implementation flaws.
Security is implementation-specific. Read the published architecture and findings ↗
Choose the length and character groups. Generate a fresh password here, on your device.
No account connection. Nothing is submitted.
No saving or sending. If copied, the password stays on your clipboard until you replace it; this page cannot clear clipboard history.
Adjust this example to a service’s requirements. This is a standalone utility, not your organisation’s enforced Vault policy.
Walk through a team handover. The useful question is who needs access, to what, and for how long.
A new person does not need every credential. Begin with the work they are responsible for.
Roles shown here are planning examples. Confirm the actual permissions in your Vault deployment.
PersonNew design teammate
CollectionDesign tools
ReviewConfirm the appropriate role
Sample context only. No account action is performed.
Keep the scope visible as a project changes hands. Review who owns the account as well as who can use it.
This preview does not invite anyone, share a password or change a permission.
ProjectAutumn campaign
CollectionCampaign accounts
ReviewOwner, membership and end date
Sample context only. No account action is performed.
Review membership and active sessions, then identify credentials that may need rotation.
Removing access cannot erase a secret someone previously copied. Follow your organisation’s offboarding and rotation process.
PersonDeparting teammate
ReviewAccess and active sessions
Follow-upRotate exposed credentials where needed
Sample context only. No account action is performed.
A concept for useful assistance: approved metadata informs a draft, and a person decides what happens next.
Role: designer · Collection: design tools
A person confirms the role and the specific items before granting access.
Prewritten example using the sample metadata shown here. No model, secret store or account is connected.
Membership: ending · Collection: campaign accounts
A person verifies access history and performs the required changes.
Prewritten example using the sample metadata shown here. No model, secret store or account is connected.
Collection: billing tools · Review: due
A person confirms who still needs access and records the outcome.
Prewritten example using the sample metadata shown here. No model, secret store or account is connected.
Illustrative concept, not a release claim. Never place passwords, recovery keys or confidential secret values in an AI prompt. Explore Celia’s role ↗
Start with the job you need to do. Open a capability for the detail to check with your team.
8 capabilities
Logins, notes and other credential records.
What to checkLength, character groups and exclusions.
What to checkA shorter path from a login page to its credential.
What to checkAccess scoped to the people who need it.
What to checkContext for reviewing access and account activity.
What to checkAn additional check at sign-in.
What to checkA plan for losing access to a device or factor.
What to checkA route into Vault—and a route out.
What to checkNo matches. Clear the search or choose another group.
Selected public feature highlights—not a guarantee for every deployment. Read the published catalogue ↗
Organise at your desk. Find a login in the browser. Keep unlock decisions on the right device.
Studio login ••••••
Project note ••••••
Service key ••••••
A central workspace for items, collections and team settings.
Native mobile apps are listed as roadmap. These views do not connect to an account or invoke biometrics.
Check current compatibility ↗Example account
example.test · sample onlyThe published Chrome extension offers item search and autofill. Confirm the supported browser and your Vault domain.
Native mobile apps are listed as roadmap. These views do not connect to an account or invoke biometrics.
Check current compatibility ↗Device verification belongs in the actual application.
ILLUSTRATION / NO DEVICE PROMPTThe desktop companion is listed for biometric unlock. Check the supported operating system, hardware and recovery path.
Native mobile apps are listed as roadmap. These views do not connect to an account or invoke biometrics.
Check current compatibility ↗A focused review to take to your security team. Open each topic for the questions behind the decision.
Ask for the deployed version, key-handling design and current derivation settings. The published security page describes both a target algorithm and a migration state; confirm the implementation rather than relying on a headline.
Review role permissions, MFA enrolment, session revocation and recovery procedures. Test the intended path with a non-sensitive account.
Request the latest assessment date, scope, unresolved findings and remediation status. Public source or a security description is not an independent audit.
Agree hosting, backups, restore testing, retention and incident responsibilities. Self-hosting changes the owner of that work; it does not remove it.
Three starting points, with the operational responsibilities made visible.
Your infrastructure. Your operations.
Plan for hosting, patching, monitoring, backups and restore tests. Request the current source and deployment documentation.
Hosted by Centilio. Scoped to your team.
Confirm account eligibility, included support, backup arrangements, retention and billing terms before purchasing.
Start with your organisation’s requirements.
Discuss identity, hosting, residency, audit and support requirements. Confirm each commitment in the agreed contract.
For 10 users per month, before taxes.
Annual estimates use the published 10% discount. Confirm the actual invoice, currency and terms with Centilio. This is not a checkout.
USD pricing checked 6 September 2026. Infrastructure costs are not included in self-hosted software pricing. Verify current plans and terms ↗
A useful evaluation is a complete path, not a promise about setup speed.
Use fictional credentials and a small test collection.
Check the intended roles, sharing and sign-in experience.
Review recovery, export and restore procedures with the owner.
Confirm responsibilities, current terms and the migration plan.
0 of 4 reviewed
Personal checklist only. It resets on reload and does not certify security, submit approval or change an account.
From hosting and recovery to the boundaries of the examples on this page.
9 answers
Ask the Vault team ↗Vault is a business password manager for organising credentials, sharing access within a team and reviewing account activity. Use the public product catalogue and a pilot to confirm the capabilities available in your deployment.
The intended design keeps plaintext credentials and usable encryption keys on the authorised client while the service stores protected records. Confirm the deployed implementation, key handling and recovery model; the phrase is not a guarantee against every attack.
No. The workspace, device and Celia examples are illustrations. They do not access credentials, change permissions, invite people or invoke biometric verification.
The generator uses your browser’s secure random source and does not submit or save the result. Reloading clears it from the page. Copying places it on your clipboard, which may retain it or sync under your device settings until you replace it.
The published pricing lists self-hosted software as free, Team at USD 5 per user per month and Enterprise as custom. Infrastructure and operations are additional for self-hosting. Yearly examples here estimate the published 10% discount; confirm taxes and current terms before purchasing.
No. The Celia fold uses prewritten examples and sample metadata, not a live model. Never put password values or recovery keys into an AI prompt. Actual product capabilities and data boundaries must be confirmed for your deployment.
The public catalogue lists import and export capabilities. Confirm the supported formats and test a small non-sensitive sample first. Keep source exports private and verify the result before changing your existing service.
The public catalogue lists a web app, a Chrome extension and a desktop companion. Native mobile apps are marked roadmap. Confirm current browser, operating-system, hardware and deployment requirements.
Review the documented recovery process before storing real credentials. Keep recovery material private, test the approved procedure with your administrator and do not paste recovery keys into this page or a support conversation.
No matching answer. Try another word or ask the Vault team.
Start a conversation, review the evidence or explore the wider Centilio system.