MARRINN

Simple · Powerful

Marrinn · The suite · Vault

Marrinn Vault.

Every team has a spreadsheet of passwords, a shared inbox with an API key in it, and one person who knows the production credentials. Vault ends all three — encrypted end to end, shared properly, and logged completely.

End-to-end encryptedThe server never sees plaintext
Zero-knowledgeNot even we can read your vault
Complete access logWho opened what, and when
Your infrastructureOn-premise, or hosted by us
The problem

Your secrets are already leaking. Quietly.

Not through a dramatic breach — through the ordinary business of getting work done. A key pasted into a chat, a password reused across four systems, a contractor who left in March and whose access nobody revoked.

✕Credentials in chat

Once a key is in a message thread it is in search results, backups and exports — permanently.

✕The shared spreadsheet

Convenient, unencrypted, unversioned, and copied to three laptops the moment it is useful.

✕Nobody rotates anything

Rotation is a manual chore, so it never happens — and old credentials stay valid for years.

✕Leavers keep access

Offboarding revokes the SSO account but not the twelve passwords they memorised or saved.

✕No idea who opened what

When something does go wrong, there is no log to tell you the blast radius.

✕Consumer tools, business risk

A browser password manager was not designed for shared production infrastructure.

How it works

Encrypted before it leaves the device.

Vault is zero-knowledge by design. Secrets are encrypted in the browser or the app with a key derived from your master passphrase, and the server only ever stores ciphertext. If someone walked out with the entire database, they would have nothing readable.

Architecture

The server holds ciphertext. That is all it holds.

Client-side encryption, per-vault keys, and a sharing model that hands out keys to people rather than copies of passwords to inboxes.

  • Client-side encryption — plaintext never crosses the network
  • Per-vault keys wrapped to each member's public key
  • Revocation actually revokes — remove access, re-wrap the vault
  • Break-glass recovery for when the person with the passphrase is unavailable
  • SSO and two-factor on top, not instead of, the encryption
Vault — infrastructure
  • Production database — root••••••••••••
  • Stripe live secret key••••••••••••
  • TLS certificate — wildcard••••••••••••
  • SMTP relay credentials••••••••••••
  • Cloud provider API token••••••••••••

5 secrets · shared with Platform team (4 members) · last opened 2 hours ago

Capabilities

Everything a team needs, nothing a team will not use.

Adoption is the whole game with a password manager. Vault is built so that the secure path is also the quick path — otherwise people go back to the spreadsheet.

Storage

Every secret type

Passwords, API keys, SSH keys, certificates, database strings, secure notes and files.

Sharing

Team vaults

Organise by team, project or environment. Membership drives access — no manual re-sharing.

Access

Role-based permissions

View, use, edit or manage. Grant time-boxed access that expires on its own.

Lifecycle

Rotation & versioning

Rotation reminders, full version history, and one-click rollback when a change breaks something.

Audit

Complete access log

Every read, edit, share and export recorded — exportable for your auditors.

Identity

SSO & two-factor

SAML and OIDC single sign-on, enforced 2FA, and offboarding that revokes everything at once.

Delivery

Where your people are

Browser extension, desktop and mobile apps, and a CLI for pipelines and servers.

Hosting

Cloud or on-premise

Run it on your own infrastructure via Docker, or let us host it. Same product either way.

Supported by AI

An assistant that watches the vault, not the contents.

The AI layer works on metadata — access patterns, ages, sharing shape, breach feeds — never on your plaintext secrets, which it cannot read either.

Risk review

Ranks the secrets most worth attention: over-shared, never rotated, or reused across systems.

Dormant access

Flags members who hold access to vaults they have not opened in months, ready to revoke.

Breach matching

Checks stored credentials against known breach corpora and tells you what to rotate first.

Sharing advisor

Spots secrets shared with the whole company that should sit with one team.

Rotation planner

Proposes a rotation order that minimises the risk of taking production down.

Log narrator

Turns the raw access log into a plain-English summary for your monthly security review.

Where it lives

Your secrets, in your jurisdiction.

A password manager is only as trustworthy as the company holding it and the country it sits in. Vault is built by a UK company, and you decide where it runs.

Self-hosted via Docker

Run the whole thing inside your own network. No outbound dependency on us to unlock your own credentials.

Or hosted by us

If you would rather not run it, we will — in the region you choose, written into your contract.

Zero-knowledge either way

Hosted or self-hosted, the encryption model is identical. We cannot read your vault in either case.

Get the passwords out of the spreadsheet.

We will walk you through Vault on your own structure — teams, environments and the credentials you are most nervous about.

Book a demo → Contact us