SENTRY · ArmorVault

A Secrets Vault We Operate. Not Software You Have To.

API keys, database credentials, TLS certificates, and service tokens are the highest-leverage attack surface in most environments — and the one most organizations manage with the least discipline. ArmorVault is Armorstack’s managed secrets service: we run the vault infrastructure, enforce the isolation boundary, and operate the rotation and audit program, so your team consumes secrets instead of babysitting a cluster.

Why This Is a Service, Not a Product

You Don’t Deploy ArmorVault. We Run It For You.

01

We Own the Infrastructure

The vault runs on Armorstack-operated infrastructure with automatic node failover and cross-datacenter replication on a defined recovery schedule. Your team never patches a Vault node, manages an unseal key, or gets paged when a cluster misbehaves — that’s our operational responsibility, not yours.

02

Isolation Enforced at the Vault Layer

Every client namespace is bound by its own Vault access-control policy. Secret operations run under your organization’s own scoped token — not a shared administrative credential — so the isolation boundary is enforced by the vault itself, not by application code that could be misconfigured.

03

A Team, Not a Support Queue

Onboarding, rotation policy, and offboarding are handled by Armorstack engineers who already know your environment — not a self-service signup flow or a ticket queue. When something needs to change, you talk to the people who run the vault.

Capabilities

What’s Actually Running Under the Hood

Per-Tenant Vault ACL Isolation

Each client’s secrets live in a dedicated namespace bound to their own access-control policy — not a shared credential that application logic has to police.

TOTP Multi-Factor + Recovery Codes

Authenticator-based MFA on every account, with one-time backup codes for lost-device recovery — no shared password resets, no support-desk social engineering surface.

Fail-Closed, Rate-Limited Audit Logging

If an audit write can’t be recorded, the read it would have logged doesn’t happen either — there is no path to an unaudited secret access.

Two-Person Offboarding Control

Permanently deleting a tenant’s secret data requires two separate administrators — the person who requests it cannot be the person who approves it.

Self-Service Team Access

Your own administrators add, review, and remove your organization’s users without waiting on an Armorstack ticket — while every change is still logged.

Rotation Age Visibility

Every credential is tracked and flagged Fresh, Aging, or Overdue — rotation stops being a spreadsheet exercise and becomes something you can see at a glance.

Where We Stand Today, Honestly

ArmorVault is live and protecting real client secrets in production today. Data is encrypted at rest under a transit seal, tenant isolation is enforced by Vault access policies, and our development process includes static analysis, CVE and secret scanning, software bill-of-materials generation, and protected-branch controls on every change.

We do not yet hold a completed SOC 2 Type II report. We would rather tell you that directly than put a badge on this page that isn’t earned yet. If your security team needs to evaluate our control environment before a completed audit exists, we’ll walk them through it directly — and we can scope a customer-sponsored audit engagement if your compliance timeline requires one.

Talk to the Team That Runs the Vault

No self-service signup, no pricing calculator. A 30-minute briefing with the engineers who actually operate ArmorVault — scoped to your environment, your compliance requirements, and your existing secrets sprawl.Schedule a Vault Security Briefing