All news

Vault: access only while you unlock it

Keys are encrypted in the browser. While the vault is locked, nothing runs on the server.

RootPilot staff cannot access your servers: they cannot see the vault password or keys, and they cannot connect to the host.

An SSH key is created on your device and encrypted with your vault password in the browser. The password never leaves the browser. RootPilot’s database keeps ciphertext only — not the vault password, and not the server password after setup.

You unlock the vault while you work: the key is decrypted in the browser for that session. Lock it — the agent and terminal stop immediately.

While the vault is locked, RootPilot does not administer the machine. Unlock it — commands run on the server you opened, and you see every step.

Vault: access only while you unlock it — RootPilot