Brain+AI

AI vault

AI vault: your keys stay yours, your AI uses them without seeing them

Your passwords and access keys leave emails, chat threads and stray files for a vault opened in your name. Nobody else reads anything in it, neither us nor your AI, and yet your automations and your agents use it every day.

What you gain

The vault is in your name

It is opened in your name, on your server or with a host in Europe. You are its administrator, and you can leave at any time with all of its contents.

Even we have no access

At handover, our access is removed and every key we may have come across during the project is changed. Need us later? You open a time-limited access, recorded in the log.

Your AI uses keys without seeing them

An agent asks for an action, and the key is added at the moment the request leaves, only towards the intended service. The model never reads it: it can neither repeat it nor send it elsewhere, even when tricked by a hidden instruction.

Everyone sees only what concerns them

One identity per person, per automation and per agent, with only the rights it needs. A contractor leaves, a key leaks: you cut that access without breaking anything else.

A key changed once, up to date everywhere

The vault feeds your tools, your hosting and your publishing pipelines. Changing a key no longer means hunting down its copies in ten files.

A log that answers in minutes

Who used which key, when, and from which tool or agent: everything is recorded. The day a doubt arises, you have an answer rather than an investigation.

Who it is for

  • Your passwords and API keys travel by email, by chat or in a shared spreadsheet.
  • You connect AI agents or automations to your tools, and nobody knows any more which key opens what.
  • An employee or a contractor has left, and you are not sure you cut all of their access.
  • A client, an auditor or your insurer asks you how your access is protected.

What you receive

  • The inventory of your secrets: where your passwords and keys live, who accesses them, and what has already leaked.
  • The search for leaks in your code repositories and their history, your publishing pipelines and your shared tools, with every exposed key revoked and replaced.
  • A vault opened in your name, on your server or with a host in Europe, organised by team and by environment.
  • Your automations and AI agents connected to the vault: each key is added at the moment of the call, never shown to the model.
  • A safeguard that blocks a secret before it enters a code repository.
  • The handover: our access removed, the keys seen during the project changed, a recovery procedure tested with your team and clear documentation.

How it goes

  1. Inventory

    We look for where your secrets live and what has already leaked. You receive the list, and every exposed key is revoked then replaced.

  2. Vault

    The vault is opened in your name and organised by team and by environment, with one identity per person, per automation and per agent.

  3. Connection

    Your tools, automations and agents move to the vault one after the other. Old copies are only deleted once the relay has been checked.

  4. Handover

    Our access is removed, the keys we came across are changed, and your team tests the recovery procedure with us.

Frequently asked questions

How can an AI use a key without seeing it?

It never receives it. It asks for an action, for example sending a quote, and a relay placed between it and the service adds the key at the moment the request leaves, only towards the intended address. Even when tricked by an instruction hidden in a document, the AI has nothing to disclose.

Is the vault home-made?

No, and that is deliberate. The core of the vault is proven open source software whose code is public: we do not reinvent encryption. Our work is to set it up in your name, connect your tools and your AI to it, then hand you the keys.

What if we lose access to the vault?

It is planned from the start: a recovery procedure, written and tested with your team, entrusts recovery to two people you designate. We keep no duplicate, since a duplicate with us would be precisely the access we promise not to have.

Do we have to migrate everything at once?

No. Tools move to the vault one by one, starting with the most exposed keys: those of AI, automations and publishing pipelines. An old copy is only deleted once the relay has been checked, so that no service stops during the project.

Does the vault replace everyone’s password manager?

No, it sits alongside it. It holds what is shared: tool accounts used by several people, API keys, tokens, database passwords. For their personal passwords, everyone keeps their own manager, with two-factor authentication wherever it exists.

Where is the data stored?

On your server or with a vault host in the European Union, always in your name. Values are encrypted, and the AI model working for you never receives them, whatever its provider.

20-minute diagnostic

Twenty minutes on a call, two or three concrete leads, no strings attached.

We look at your situation, identify what can be automated or improved, and tell you plainly whether we can help.

WhatsApp