Why your startup's credentials vault should be zero-knowledge
Ask a ten-person startup where the Stripe key is. The honest answer is usually a pinned message, a shared doc, or a founder's password manager that nobody else can open. It is not carelessness. The tools built for this were built for IT departments, and a startup does not have one.
What zero-knowledge means
A zero-knowledge vault is one where the server stores your secrets but cannot read them. Encryption and decryption happen in the browser, with keys derived from each person's password, and the password never leaves the device. If the server is breached, the attacker gets ciphertext. If the vendor is subpoenaed, the vendor hands over ciphertext. If a disgruntled vendor employee looks, they see ciphertext.
That is a different promise from "encrypted at rest", which only means the disk is encrypted and the server decrypts everything when it needs to. Most SaaS tools are encrypted at rest. Very few are zero-knowledge, because it is harder to build and it removes the vendor's ability to help you when things go wrong.
How ShipWoven does it
- Your browser derives two keys from your password: one to sign in, one that protects your private key. Only the first is sent to the server.
- Each credential, payment and legal document gets its own key, and that key is wrapped for every person who may read the section, using their public key.
- The server stores ciphertext, public keys and the list of who may read what. It never stores a password, a private key or a plaintext secret.
- Every reveal is recorded: who looked at which entry, when.
The hard part is recovery
A system without a back door has to answer: what happens when someone forgets their password? The answer is a recovery kit, a file each person saves when they enrol, which restores their private key after a password reset. If the kit is lost, a super admin re-shares the entries with the person's new keys. The server never recovers anything, because it cannot, and that is the point.
The other hard part is people leaving
When someone leaves, their access must end and the secrets they could read must change. A vault that only removes their account leaves them with every key they ever saw. ShipWoven rotates the affected entries to new keys and re-wraps them for the people who remain. It takes a super admin a minute, and the audit trail shows it was done.
Why it belongs inside the team portal
The reason keys end up in chat is that the vault is somewhere else. When the vault lives next to the reports, the roadmap and the people, with access that follows the same departments and teams, there is nowhere easier to put a key than the right place. Finance and legal follow the same model: the company's payments with their receipts, and its NDAs, employment contracts and passports, all sealed in the browser and shared only with the people whose job it is.
The full design is on our security page. If you would rather see it than read it, ask for a walkthrough.