ISO-27001
Tamper-resistant audit log
Complete, metadata-based event trails form a reliable audit trail — transparency for internal reviews without exposing sensitive content.
Local-First Security
OxidVault combines secret management with Local-First Security — your data stays in your infrastructure, no cloud, no trust required.
Your data stays on your server — no cloud contract, no external provider.
The OxidVault Desktop Safe combines clear secret management with enterprise-grade governance. Secrets, audit trails, and policies remain in a controlled interface.
Built for CTOs, IT security leaders, and compliance officers in SMBs who expect technical precision and traceable control.
ISO-27001
Complete, metadata-based event trails form a reliable audit trail — transparency for internal reviews without exposing sensitive content.
Centrally defined, locally enforced. Binding governance standards across all teams.
AES-256-GCM
Secrets processed locally. No cloud dependency, no external exposure.
Extension communicates via Native Messaging directly with the desktop client — no cloud intermediary, smaller attack surface, full auditability.
Up to 5 users in the Community Edition — each with their own password and 2FA. Enterprise: unlimited users, LDAP, and SSO.
Core OxidVault workflows — visual and practical for secure operations in your team. Click an image to enlarge.
Seamless web login: the extension connects locally to the Desktop Safe via Native Messaging — without a cloud intermediary.
Install from Chrome Web Store →One click to your server: integrated SSH client without manual configuration.
Version control for your secrets: Git-based synchronization for maximum transparency.
Full compliance: complete history of all access and changes in real time.
Secret management, not a password list: six entry types for everything your team secures daily.
OxidVault relies on a direct connection between the browser extension and the local desktop client. Sensitive data stays in your controlled environment and supports a robust governance model.
Result: no mandatory cloud hop, reduced attack surface, clear transparency, and digital sovereignty in security-critical workflows.
Radical transparency: the OxidVault Desktop Safe is fully open source. Anyone can review, audit, and compile the code on GitHub.
Open repository on GitHubThree steps to secure, local OxidVault deployment in your organization.
01
Review the source code, verify the build process, and deploy the Desktop Safe from a trusted source.
02
Roll out the browser extension in your environment and align it with your internal security policies.
Chrome Web Store →03
Enable Native Messaging, pair the desktop client, and work productively without cloud dependency.
Details on the Community and Enterprise editions are underEditions.
Both editions run entirely on your own infrastructure — the difference is feature scope, not data sovereignty.
COMMUNITY EDITION
AGPLv3Open Source · up to 5 users
# community.toml
users = 5
sso = false
ldap = false
license = "AGPLv3"
ENTERPRISE EDITION
On requestOn request · for larger teams
# enterprise.toml
users = "unlimited"
sso = true
ldap = true
sla = "priority"
Answers to the most important questions before deployment in your organization.
All data stays exclusively in your infrastructure — no transfer to external servers. The ISO-27001-compliant audit trail documents access and changes for data protection officers and auditors.
Exclusively with you — on your local machine, file server, or network drive (UNC path). OxidVault has no access to your data. No cloud, no third-party hosting, no external infrastructure.
Community Edition: up to 5 users per vault, each with their own password and 2FA. For teams of 6 or more, or with LDAP/SSO requirements, the Enterprise Edition is available. Inquire →
The Community Edition is permanently free (AGPLv3). The Enterprise Edition with unlimited users, LDAP/AD, and priority support is available on request. Request a quote →
Fully. Encryption, MFA, and audit logging work without an internet connection. A connection is only optionally required for Git Sync or the browser extension on the local network.
Fully open source on GitHub — reviewable, auditable, and compilable at any time. Enterprise customers receive a commercial license model without AGPLv3 obligations. GitHub →
Windows is fully supported today (MSI installer). Linux and macOS are planned — the Rust/Tauri core is cross-platform; installers will follow in an upcoming release.
More questions? Get in touch →
Talk to us about secure rollouts, governance requirements, and integration questions in your organization.