stelixvault

Features

A vault that also knows how to open the door.

Most managers stop at the password: they show it to you, and you retype it elsewhere. Vault completes the gesture. Section by section, what is inside — and nothing that isn't.

The vault

One vault per team, per client, per site.

Each vault has its members and its rights. A colleague added sees the vault appear on their own; a colleague removed has nothing left — without a single password having to change.

  • Private and shared vaults, per-person rights
  • History of every access, on the server
  • Trash and archive: nothing is destroyed by one click too many
  • Import from Bitwarden (JSON), 1Password (CSV) and any CSV export: KeePass, spreadsheets

Sharing

Share without sending.

A sharing link carries its key in the URL fragment — the part a browser never sends to the server. It expires on its own, and its read counter is visible. The drop box does the opposite: a client hands you a secret without it going through email.

  • Time-limited links, bounded number of reads
  • Drop boxes to receive a credential
  • One-time codes (TOTP) stored with the credential
  • Second factor required for sensitive actions

Browser

The extension holds nothing.

It relays an autofill request to the application, which decides. No copy of the vault in the browser: a compromised browser takes nothing. The site must match exactly — no "contains" that lets phishing through.

  • Chrome, Edge, Brave
  • List of authorised sites, revocable
  • No secret stored on the browser side
  • Native messaging, no open port

Terminal

The session opens from the record.

SSH, Telnet, serial console: the connection starts from the server's record, with the vault's password or SSH key, without ever displaying them. SFTP file transfer lives in the same window, with its queue and resume.

  • SSH, Telnet, serial terminal
  • SSH keys stored in the vault and referenced by servers
  • SFTP with queue, resume, log
  • Live server metrics during the session

Racks

The plan and the vault never drift apart.

A rack is no longer a drawing: it is an inventory. What is mounted where, on which outlet, with which address. The servers on the plan are those in the vault, and the client record says who owns what.

  • Rack plans in three dimensions
  • IP addressing: blocks, allocations, next free address
  • Power: outlet strips, power supplies, connections
  • Client records and intervention history

Team

What the team is doing, and who is there.

A shared task list that two people can write at the same time, everyone's presence, and an audit log kept on the server: who opened what, when, from where.

  • Shared tasks, subtasks, assignment, reminders
  • Real-time presence
  • Audit log on the server
  • Administration of accounts, roles and devices

What next

All of this is in Forge. The vault alone is Cercle.