Skip to content
OxidVault

Local-First Security

Passwords secure. Local. Offline. GDPR-compliant.

OxidVault combines secret management with Local-First Security — your data stays in your infrastructure, no cloud, no trust required.

oxidvault://desktop-safe

Clearly structured. Secure in daily use.

Your data stays on your server — no cloud contract, no external provider.

The OxidVault Desktop Safe combines clear secret management with enterprise-grade governance. Secrets, audit trails, and policies remain in a controlled interface.

  • Fast access to vaults, entries, and compliance status
  • Audit log and security dashboard directly in your workflow
  • Minimalist UI design for focused administration
Screenshot of the OxidVault user interface

oxidvault://features

Features for governance, compliance, and ISO-27001 audit trail

Built for CTOs, IT security leaders, and compliance officers in SMBs who expect technical precision and traceable control.

LOG

ISO-27001

Tamper-resistant audit log

Complete, metadata-based event trails form a reliable audit trail — transparency for internal reviews without exposing sensitive content.

POL

Policy Management

Centrally defined, locally enforced. Binding governance standards across all teams.

ENC

AES-256-GCM

Local encryption

Secrets processed locally. No cloud dependency, no external exposure.

EXT

Native browser integration

Extension communicates via Native Messaging directly with the desktop client — no cloud intermediary, smaller attack surface, full auditability.

USR

Multi-User Vault

Up to 5 users in the Community Edition — each with their own password and 2FA. Enterprise: unlimited users, LDAP, and SSO.

up to 5 users

oxidvault://screenshots

Features at a glance

Core OxidVault workflows — visual and practical for secure operations in your team. Click an image to enlarge.

EXT

Browser Extension

Seamless web login: the extension connects locally to the Desktop Safe via Native Messaging — without a cloud intermediary.

Install from Chrome Web Store →
SSH

SSH Quickconnect

One click to your server: integrated SSH client without manual configuration.

GIT

Git Sync

Version control for your secrets: Git-based synchronization for maximum transparency.

LOG

Audit Logs

Full compliance: complete history of all access and changes in real time.

  • Logs access, changes, and shares per secret
  • No plaintext secrets in the log — metadata only
  • Export as CSV, JSON, or PDF for audits and reviewers
TYPE

More than just passwords

Secret management, not a password list: six entry types for everything your team secures daily.

  • Web login, SSH key, and API token in a single vault
  • Structured database and network/Wi-Fi credentials
  • Secure notes for configs and internal records

oxidvault://architecture

Trust through local data sovereignty

OxidVault relies on a direct connection between the browser extension and the local desktop client. Sensitive data stays in your controlled environment and supports a robust governance model.

  1. 1. Browser extensiondetects login contexts and sends targeted requests.
  2. 2. Native Messaging Hosttransfers messages locally via standardized OS mechanisms.
  3. 3. Desktop Clientchecks vault status and delivers only the data required.

Result: no mandatory cloud hop, reduced attack surface, clear transparency, and digital sovereignty in security-critical workflows.

oxidvault://open-source

Transparency & Open Source

Radical transparency: the OxidVault Desktop Safe is fully open source. Anyone can review, audit, and compile the code on GitHub.

Open repository on GitHub

oxidvault://quickstart

Quick start guide

Three steps to secure, local OxidVault deployment in your organization.

  1. 01

    Get the Desktop Safe from GitHub

    Review the source code, verify the build process, and deploy the Desktop Safe from a trusted source.

  2. 02

    Install the extension

    Roll out the browser extension in your environment and align it with your internal security policies.

    Chrome Web Store →
  3. 03

    Establish the local connection

    Enable Native Messaging, pair the desktop client, and work productively without cloud dependency.

Details on the Community and Enterprise editions are underEditions.

oxidvault://editions

No subscription. No lock-in.

Both editions run entirely on your own infrastructure — the difference is feature scope, not data sovereignty.

COMMUNITY EDITION

AGPLv3
€0/ forever

Open Source · up to 5 users

# community.toml

users = 5

sso = false

ldap = false

license = "AGPLv3"

  • 5 users per vault — each with their own password and 2FA
  • Team vaults, browser extension, audit log, Git sync, SSH Quick Connect
  • 100% local data storage, no cloud dependency
  • Full source code on GitHub
Download for free

ENTERPRISE EDITION

On request

On request · for larger teams

# enterprise.toml

users = "unlimited"

sso = true

ldap = true

sla = "priority"

  • Unlimited users per vault
  • LDAP integration and SSO
  • Everything in the Community Edition
  • Priority support and SLA
Get in touch →

oxidvault://faq

Frequently asked questions

Answers to the most important questions before deployment in your organization.

Is OxidVault GDPR-compliant?

All data stays exclusively in your infrastructure — no transfer to external servers. The ISO-27001-compliant audit trail documents access and changes for data protection officers and auditors.

Where are my passwords stored?

Exclusively with you — on your local machine, file server, or network drive (UNC path). OxidVault has no access to your data. No cloud, no third-party hosting, no external infrastructure.

How many users can I create?

Community Edition: up to 5 users per vault, each with their own password and 2FA. For teams of 6 or more, or with LDAP/SSO requirements, the Enterprise Edition is available. Inquire →

What does OxidVault cost?

The Community Edition is permanently free (AGPLv3). The Enterprise Edition with unlimited users, LDAP/AD, and priority support is available on request. Request a quote →

Does OxidVault work offline?

Fully. Encryption, MFA, and audit logging work without an internet connection. A connection is only optionally required for Git Sync or the browser extension on the local network.

Is the source code available for review?

Fully open source on GitHub — reviewable, auditable, and compilable at any time. Enterprise customers receive a commercial license model without AGPLv3 obligations. GitHub →

Which operating systems does OxidVault support?

Windows is fully supported today (MSI installer). Linux and macOS are planned — the Rust/Tauri core is cross-platform; installers will follow in an upcoming release.

More questions? Get in touch →

oxidvault://contact

Contact

Talk to us about secure rollouts, governance requirements, and integration questions in your organization.

Send a B2B inquiry