You Don’t Deploy ArmorVault. We Run It For You.
We Own the Infrastructure
The vault runs on Armorstack-operated infrastructure with automatic node failover and cross-datacenter replication on a defined recovery schedule. Your team never patches a Vault node, manages an unseal key, or gets paged when a cluster misbehaves — that’s our operational responsibility, not yours.
Isolation Enforced at the Vault Layer
Every client namespace is bound by its own Vault access-control policy. Secret operations run under your organization’s own scoped token — not a shared administrative credential — so the isolation boundary is enforced by the vault itself, not by application code that could be misconfigured.
A Team, Not a Support Queue
Onboarding, rotation policy, and offboarding are handled by Armorstack engineers who already know your environment — not a self-service signup flow or a ticket queue. When something needs to change, you talk to the people who run the vault.
What’s Actually Running Under the Hood
Per-Tenant Vault ACL Isolation
Each client’s secrets live in a dedicated namespace bound to their own access-control policy — not a shared credential that application logic has to police.
Bring-Your-Own-Key Encryption
Supply your own KMS key and Armorstack becomes architecturally unable to decrypt your secrets — not a policy promise, a cryptographic one.
TOTP Multi-Factor + Recovery Codes
Authenticator-based MFA on every account, with one-time backup codes for lost-device recovery — no shared password resets, no support-desk social engineering surface.
Fail-Closed, Rate-Limited Audit Logging
If an audit write can’t be recorded, the read it would have logged doesn’t happen either — there is no path to an unaudited secret access.
Two-Person Offboarding Control
Permanently deleting a tenant’s secret data requires two separate administrators — the person who requests it cannot be the person who approves it.
Self-Service Team Access
Your own administrators add, review, and remove your organization’s users without waiting on an Armorstack ticket — while every change is still logged.
Rotation Age Visibility
Every credential is tracked and flagged Fresh, Aging, or Overdue — rotation stops being a spreadsheet exercise and becomes something you can see at a glance.
Where We Stand Today, Honestly
ArmorVault is live and protecting real client secrets in production today. Data is encrypted at rest under a transit seal, tenant isolation is enforced by Vault access policies, and our development process includes static analysis, CVE and secret scanning, software bill-of-materials generation, and protected-branch controls on every change. ArmorVault is built for regulated mid-market organizations, typically 100–2,000 employees, and is evaluated most often by a CISO or Head of Security weighing it against HashiCorp Cloud Platform Vault, CyberArk Conjur, Akeyless, or Doppler.
We do not yet hold a completed SOC 2 Type II report. We would rather tell you that directly than put a badge on this page that isn’t earned yet. If your security team needs to evaluate our control environment before a completed audit exists, we’ll walk them through it directly — and we can scope a customer-sponsored audit engagement if your compliance timeline requires one.
Talk to the Team That Runs the Vault
No self-service signup. No pricing calculator. A working session with the engineers who operate ArmorVault — scoped to your environment, compliance requirements, and secrets sprawl.