SENTRY · ArmorVault

A secrets vault we operate — not software you babysit.

API keys, database credentials, TLS certificates, and service tokens are high-leverage attack surface. ArmorVault runs under Sentry: we operate the vault, enforce the isolation boundary, and run rotation and audit — your team consumes secrets instead of patching a cluster.

Why This Is a Service, Not a Product

You Don’t Deploy ArmorVault. We Run It For You.

01

We Own the Infrastructure

The vault runs on Armorstack-operated infrastructure with automatic node failover and cross-datacenter replication on a defined recovery schedule. Your team never patches a Vault node, manages an unseal key, or gets paged when a cluster misbehaves — that’s our operational responsibility, not yours.

02

Isolation Enforced at the Vault Layer

Every client namespace is bound by its own Vault access-control policy. Secret operations run under your organization’s own scoped token — not a shared administrative credential — so the isolation boundary is enforced by the vault itself, not by application code that could be misconfigured.

03

A Team, Not a Support Queue

Onboarding, rotation policy, and offboarding are handled by Armorstack engineers who already know your environment — not a self-service signup flow or a ticket queue. When something needs to change, you talk to the people who run the vault.

Capabilities

What’s Actually Running Under the Hood

Per-Tenant Vault ACL Isolation

Each client’s secrets live in a dedicated namespace bound to their own access-control policy — not a shared credential that application logic has to police.

Bring-Your-Own-Key Encryption

Supply your own KMS key and Armorstack becomes architecturally unable to decrypt your secrets — not a policy promise, a cryptographic one.

TOTP Multi-Factor + Recovery Codes

Authenticator-based MFA on every account, with one-time backup codes for lost-device recovery — no shared password resets, no support-desk social engineering surface.

Fail-Closed, Rate-Limited Audit Logging

If an audit write can’t be recorded, the read it would have logged doesn’t happen either — there is no path to an unaudited secret access.

Two-Person Offboarding Control

Permanently deleting a tenant’s secret data requires two separate administrators — the person who requests it cannot be the person who approves it.

Self-Service Team Access

Your own administrators add, review, and remove your organization’s users without waiting on an Armorstack ticket — while every change is still logged.

Rotation Age Visibility

Every credential is tracked and flagged Fresh, Aging, or Overdue — rotation stops being a spreadsheet exercise and becomes something you can see at a glance.

Where We Stand Today, Honestly

ArmorVault is live and protecting real client secrets in production today. Data is encrypted at rest under a transit seal, tenant isolation is enforced by Vault access policies, and our development process includes static analysis, CVE and secret scanning, software bill-of-materials generation, and protected-branch controls on every change. ArmorVault is built for regulated mid-market organizations, typically 100–2,000 employees, and is evaluated most often by a CISO or Head of Security weighing it against HashiCorp Cloud Platform Vault, CyberArk Conjur, Akeyless, or Doppler.

We do not yet hold a completed SOC 2 Type II report. We would rather tell you that directly than put a badge on this page that isn’t earned yet. If your security team needs to evaluate our control environment before a completed audit exists, we’ll walk them through it directly — and we can scope a customer-sponsored audit engagement if your compliance timeline requires one.

Talk to the Team That Runs the Vault

No self-service signup. No pricing calculator. A working session with the engineers who operate ArmorVault — scoped to your environment, compliance requirements, and secrets sprawl.