Credential Vault

Every client credential, encrypted and access-logged

Lexful stores all client credentials encrypted at rest. Nothing is visible until a tech explicitly reveals it. Every reveal creates a timestamped log entry, so you always know who accessed what and when.

Hartwell Construction AES-256
Fortigate Admin ••••••••••••
Exchange Admin ••••••••••••
Veeam Backup ••••••••••••
AD Domain Admin ••••••••••••
How it Works

Credentials linked to the runbooks that use them

A credential in Lexful is not a standalone record. It's linked to the client environment, the assets it accesses, and every runbook that references it. When a tech follows a runbook step, the credential link is right there.

  • Import from CSV, password manager export, or manual entry
  • Auto-linked when runbooks reference a service by name
  • Tags by environment, device type, and credential category
  • Rotation reminders when a credential hasn't changed in 90 days
  • Search across all clients without exposing values
Security Model

Zero-knowledge: the server stores ciphertext, not passwords

Client-side encryption

Credentials are encrypted with AES-256-GCM before they leave your browser. The Lexful server receives and stores ciphertext. Plaintext never crosses the network.

Immutable access log

Every credential reveal produces a signed, tamper-evident log entry. Log entries cannot be edited or deleted, even by admins. Export the log at any time for compliance review.

Anomaly alerts

If a credential is accessed at an unusual hour, from an unusual IP, or more than 5 times in an hour, Lexful sends an alert to your account admin immediately.

Use Cases

The credential scenarios Lexful handles

Offboarding a tech

When a tech leaves, revoke their access in Lexful. Their credential reveals stop instantly. The credentials themselves remain accessible to the team. No password rotation campaign required for the team to lose access to the departed tech.

Client audit prep

A client asks who has access to their admin credentials. Pull the credential access log in two clicks, filter by client, and export a CSV showing every access event for the last 90 days.

Credential consolidation

Your team uses three different password managers across different client accounts. Import them all into Lexful, one search, all credentials. One vault, every client, consistent access controls.

Rotation tracking

Lexful tracks when each credential was last changed. When a password hasn't rotated in 90 days, the vault flags it. Keep your client environments compliant without manual tracking in a spreadsheet.

Ready to consolidate

One vault for every client's credentials

Import your existing credentials in minutes. AES-256 encrypted, access-logged, and linked to the runbooks that need them.