A key that never leaves the box
On Windows the wrapping key that seals the vault is a non-exportable TPM key — RSA-2048 in the platform crypto provider, sealed to this appliance and working even on a vTPM. That's the hardware-backed root.
Credential vault
Device logins, saved passwords and secure notes belong in one encrypted place — not a spreadsheet or a config file. Skans seals every secret with a key that never leaves the appliance — a non-exportable TPM key on the Windows appliance — uses it internally without ever putting it on screen, and records every reveal and copy in the audit log. You own the keys; nothing leaves the wire.

One place, entered once
Every device and service credential Skans holds lives in one encrypted place — plus the saved passwords and secure notes your team would otherwise scatter across spreadsheets. You enter each one once through the console; it's encrypted on the way in and never written to a plaintext file.

How it's protected
On Windows the wrapping key that seals the vault is a non-exportable TPM key — RSA-2048 in the platform crypto provider, sealed to this appliance and working even on a vTPM. That's the hardware-backed root.
Envelope encryption: every credential gets its own AES-256-GCM data key, wrapped by a key-encryption key, sealed by the TPM. No two secrets ever share a key.
Each ciphertext is tied to its exact device and field with authenticated data. Lift a blob onto another device or column and it simply fails to decrypt — a copied secret can't be replayed where it doesn't belong.
No usable TPM? Skans falls back to DPAPI or a permission-locked keyfile — and says so; only the TPM path is reported as hardware-backed. The appliance runs FIPS approved-mode, which it never dresses up as CMVP validation.
Nothing revealed off the record
Skans uses a stored credential internally without ever putting it on screen. Surfacing one again is a separate, deliberate action — and it never happens silently.

Coverage, not guesswork
A vault is only as good as its coverage. The Passwords page rolls up the whole fleet — which devices have a stored login, which are missing one, and which haven't been changed in too long — all from a projection that never decrypts a thing.

Resilient by design
Your credentials are protected in ways that outlast the appliance they live on, and kept apart from the machine secrets the box runs on itself.

Talk to us
Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.