centilio
Centilio

Explore the products

A business OS.
Room to grow.

Start with one tool. Explore the wider suite as your needs grow.

Explore Centilio One ↗Product availability follows the catalogue.
CENTILIO VAULT / SECURITY

Understand the boundary.
Ask for the evidence.

A useful security conversation connects the intended design, the running version and the people responsible for it.

VAULT / DESIGN

Know what the boundary means.

  • 01
    ContentsHow items are protected
  • 02
    KeysWhere custody belongs
  • 03
    EndpointsWhat remains at risk

Illustrative planning view · no account connected

THE PRIVACY PRINCIPLE

Keep the secret.
Protect the handover.

Explore the intended boundary in three steps. This is an explanatory model, not a live encryption trace.

DEVICE / PRIVATE CONTEXT

Your authorised device

Credential content stays inside the intended protection boundary.

SERVICE / PROTECTED RECORD

Nothing to transfer yet.

Start with the device and session you trust. This diagram contains no real password.

Security is implementation-specific. Read the published architecture and findings ↗

FOR THE SECURITY BUYER

Trust deserves evidence.
Not just a label.

A focused review to take to your security team. Open each topic for the questions behind the decision.

01 / IMPLEMENTATION

What is running in this deployment?

Ask for the deployed version, key-handling design and current derivation settings. The published security page describes both a target algorithm and a migration state; confirm the implementation rather than relying on a headline.

02 / ACCESS AND RECOVERY

Who can regain or change access?

Review role permissions, MFA enrolment, session revocation and recovery procedures. Test the intended path with a non-sensitive account.

03 / INDEPENDENT EVIDENCE

What has actually been assessed?

Request the latest assessment date, scope, unresolved findings and remediation status. Public source or a security description is not an independent audit.

04 / OPERATIONS

Who owns the operational work?

Agree hosting, backups, restore testing, retention and incident responsibilities. Self-hosting changes the owner of that work; it does not remove it.

RECOVERY / CONTINUITY

Prepare for the day
that does not go to plan.

Review scenarios, not just settings.

A CLOSER LOOK / LOST DEVICE

Start with the documented recovery path.

A missing device changes the access problem; do not improvise with confidential material.

What this example means

Follow your organisation’s process. This preview does not revoke sessions or recover an account.

VAULT / ILLUSTRATIVE BRIEF
01

IdentifyAccount and affected device

02

ContainReview and revoke supported sessions

03

RecoverUse the approved recovery process

Sample context only. No account action is performed.

PRIVATE REPORTING

Raise a concern.
Protect the evidence.

Use the verified official channel; keep secret values out of ordinary messages.

01

What to include

Describe the affected version, expected and observed behaviour, timestamps and minimal redacted reproduction steps. Do not include passwords, recovery keys, session tokens or full credential exports.

02

Where to send it

Open the official Vault security page for its private disclosure contact. Confirm the secure transfer method before sharing sensitive evidence. This page does not submit a report or promise a response time.

Official security page and reporting channel ↗ · reviewed 6 September 2026. This marketing preview is not a security assessment.

QUESTIONS / ANSWERED

A little more clarity.

Open a question, or search for what you need.

6 answers

What does client-side encryption protect?

It is intended to protect item contents before storage or transfer. Its strength depends on the running implementation, key custody, authentication and endpoints. It does not eliminate every attack or operational risk.

Which key-derivation algorithm is currently deployed?

The published security page describes Argon2id in its diagram and a PBKDF2-to-Argon2id migration in its findings. Ask for the exact deployed version and configuration; this preview does not resolve that inconsistency by assertion.

Is there an independent security assessment?

Request the latest report, assessment date, scope and remediation status. Public source or a security page is not evidence that the current deployment has passed an independent assessment.

Can support always recover a lost vault?

Do not assume that it can. Review the supported recovery model before onboarding and test it with non-sensitive data. Never send support a master password or recovery key.

Does removing a member remove every copy of a secret?

No. Revoke supported access and sessions, and rotate credentials that may have been copied or exposed according to your organisation’s process.

How should a suspected vulnerability be reported?

Use the private reporting channel listed on the official security page. Share minimal redacted evidence and ask for a secure transfer method before sending sensitive details.

THE NEXT STEP

Keep the decision
moving forward.

Explore the next page or bring your requirements to the Vault team.