Key, secret, and certificate management

Key, secret, and cert management made simple.

No more keys scattered across your messages and files. One shared vault with PGP, SSH, certificates, rotation, and one-time share links — more secure than a shared file, less overhead than enterprise PKI.

No more credential sprawl

One shared vault for the whole org — projects and folders keep work organized.

Real cryptography

PGP, SSH, and X.509 built in — generate or import what you already have.

Fewer expired keys

Version history, rotation policies, and expiry tracking keep secrets current.

Protected by default

Sensitive fields encrypted at rest and decrypted locally in your browser.

See everything in one place

Folders, projects, and detail views for keys, secrets, notes, and certificates — inspect a deploy key, check expiry, and share once without leaving the vault.

Build your secure vault

Built for how engineering teams work — crypto-native, shared, and auditable.

PGP & SSH keys

Generate, import, and manage key pairs in the vault.

Secrets & notes

Store credentials with versioning and optional rotation.

Certificates

Full X.509 lifecycle — CSR, issued cert, and private key in one resource.

Share links

One-time links that expire — no more Slack messages.

Projects & folders

Split vaults by team or environment; organize with folders.

Bulk import

Import existing keys and certs in one click.

Team

Let's Encrypt issuance

Issue and renew Let's Encrypt TLS certificates directly from the vault.

Team

File crypto

Encrypt, sign, or verify files with vault keys.

Team

Audit & access

Org audit log and role-based access across projects.

Coming Soon

API access

Read-only vault access via REST API.

Coming Soon

Cloud KMS sync

Sync items with your chosen cloud KMS provider.

End-to-end security

Trustworthy by design — no plaintext sensitive data flying around the internet (or in our databases).

  • Envelope encryption — sensitive fields never stored as plaintext
  • Decrypted locally in your browser, not exposed in API responses
  • Role-based access — control who sees what across projects
  • Super Admin controls team invites and access
  • One-time share links with expiry and optional password protection
  • Audit trail for all vault actions (Team plan only)

Plans for every team

Free plan to get started, or more advanced features for growing teams.

Free

$0/ user / month

1 user

Get started for free

  • Keys, secrets, certificates, and secure notes
  • Ideal for evaluating before your team commits
Start free

Coffee

$5/ user / month

1 user

Support the project

  • Same as Free plan
  • Support ongoing development
Get started

Team Pro

$25/ user / month

Unlimited users

Minimum 10 users · from $250/month

  • Everything in Team
  • Fine-grained RBAC
  • More advanced features coming soon
Get started

Common questions

Still deciding? Here's what teams usually ask before getting started.

How do I sign up?

Create an account on the registration page — no invite required. You'll set up your organization and can invite team members from there.

How is this different from 1Password or Bitwarden?

Password managers focus on login credentials. SimpleKrypt is built for engineering teams managing PGP and SSH keys, X.509 certificates, deploy secrets, and file crypto — with org-wide sharing, audit logs, and one-time share links.

Do you store secrets as plaintext?

No. Sensitive vault fields use envelope encryption — the API returns ciphertext, and the app decrypts locally in your browser. Names, folders, and fingerprints stay readable for browse and search.

What happens when someone leaves the team?

Super Admins can revoke access instantly. Per-user encryption keys mean removing a member removes their ability to decrypt shared resources. Audit logs show who changed what, and when.