Every client credential, encrypted and access-logged
Lexful stores all client credentials encrypted at rest. Nothing is visible until a tech explicitly reveals it. Every reveal creates a timestamped log entry, so you always know who accessed what and when.
Credentials linked to the runbooks that use them
A credential in Lexful is not a standalone record. It's linked to the client environment, the assets it accesses, and every runbook that references it. When a tech follows a runbook step, the credential link is right there.
- Import from CSV, password manager export, or manual entry
- Auto-linked when runbooks reference a service by name
- Tags by environment, device type, and credential category
- Rotation reminders when a credential hasn't changed in 90 days
- Search across all clients without exposing values
Zero-knowledge: the server stores ciphertext, not passwords
Client-side encryption
Credentials are encrypted with AES-256-GCM before they leave your browser. The Lexful server receives and stores ciphertext. Plaintext never crosses the network.
Immutable access log
Every credential reveal produces a signed, tamper-evident log entry. Log entries cannot be edited or deleted, even by admins. Export the log at any time for compliance review.
Anomaly alerts
If a credential is accessed at an unusual hour, from an unusual IP, or more than 5 times in an hour, Lexful sends an alert to your account admin immediately.
The credential scenarios Lexful handles
Offboarding a tech
When a tech leaves, revoke their access in Lexful. Their credential reveals stop instantly. The credentials themselves remain accessible to the team. No password rotation campaign required for the team to lose access to the departed tech.
Client audit prep
A client asks who has access to their admin credentials. Pull the credential access log in two clicks, filter by client, and export a CSV showing every access event for the last 90 days.
Credential consolidation
Your team uses three different password managers across different client accounts. Import them all into Lexful, one search, all credentials. One vault, every client, consistent access controls.
Rotation tracking
Lexful tracks when each credential was last changed. When a password hasn't rotated in 90 days, the vault flags it. Keep your client environments compliant without manual tracking in a spreadsheet.
One vault for every client's credentials
Import your existing credentials in minutes. AES-256 encrypted, access-logged, and linked to the runbooks that need them.