A place for credentials.
A scope for every agent.
VaultPerch lets people and agent owners keep credentials in scoped vaults, approve receiving devices, and withdraw future access from one place.
This first increment is invitation-only, with no billing during the pilot. Sign in or open the invitation sent to your email address.
Read the setup guideDiscuss a pilot invitationImport deliberately
Choose a vault and submit a credential through the trusted browser or protected CLI input.
Approve a receiver
Give an agent a named principal, a limited grant and an explicitly approved device.
Revoke future access
Stop new VaultPerch deliveries. Rotate the provider credential separately if it may have been exposed.
A useful first release.
The invited pilot offers verified email and password onboarding, vault and principal management, credential import, approved receiver enrollment, two-device handoff, and revocation. Use the browser at app.vaultperch.com and the CLI with the API origin https://api.vaultperch.com.
The version 0.1.0 CLI supports Apple Silicon Macs running macOS 14 or later with Node.js 24 installed. It bundles a native Keychain helper and supports an explicitly selected protected service-account directory on that configuration. Install the CLI and verify its checksum.
Linux, hosted MCP and native HOS integration are upcoming. Intel Macs and other platform variants are not offered in this first increment.
Know who holds
the keys.
VaultPerch is a custodial service operated by CognitionHub.com Ltd. It encrypts stored credential values with per-vault keys wrapped by separate server-held keys. This is not zero-knowledge storage: a privileged operator or compromised server could gain access.
After delivery, a receiving process can copy or use the credential. Revocation stops future VaultPerch admission; it cannot recall a credential already delivered or revoke it at its provider.
Password reset uses the verified mailbox and invalidates owner sessions. A separate compromised-account choice also revokes agent enrollments. Losing the mailbox requires operator review of pre-existing continuity evidence; recovery may be refused if continuity cannot be established.
Loss of all applicable encryption and recovery keys makes retained credentials unrecoverable. Owner inventory snapshots and restore require deliberate review and confirmation; restore can lose newer data and leaves restored access inactive until you prepare fresh access and review activation. See the recovery procedure. No availability, recovery-time or retention SLA is offered here.
A small pilot.
A direct contact.
Questions, invitations and recovery support: support@vaultperch.com.
Report suspected exposure or a security defect privately to security@vaultperch.com. Include affected resource references and times, without passwords, tokens or credential values.
Privacy
This static website uses no third-party scripts, trackers or analytics and has no access to vault bindings or app authentication cookies. Hosting infrastructure receives ordinary request metadata such as network address and requested URL.
The app processes your email address, authentication records, vault and access metadata, encrypted credentials, and limited security/operational records to operate the service. Transactional email and hosting use Cloudflare. Operator access and encryption custody are described above. Contact support about privacy or deletion. This pilot offers no retention or deletion-time SLA.
Never send credentials in support email. Correspondence is used to handle your request and any related security or recovery case.
Pilot terms
Operator: CognitionHub.com Ltd. Access is by invitation only, for authorized use of credentials you are entitled to manage. No billing, uptime SLA or guarantee of compatibility is offered for the pilot.
Start with a synthetic credential to check your receiver and workflow before importing credentials for your own work. You remain responsible for provider-side permissions, credential rotation, receiving processes and independent mailbox access. Access may be suspended for abuse, exposure or recovery concerns. Contact support before entrusting a workflow that depends on uninterrupted availability.
These pilot terms do not remove rights that cannot lawfully be excluded. Changes to the offered service and material limits will be documented for invited users.