VaultPerch
Upcoming invited pilot

A place for credentials.
A scope for every agent.

VaultPerch is being built to let people and agent owners keep credentials in scoped vaults, approve receiving devices, and withdraw future access from one place.

Invitation-only. No billing during the pilot. Runtime acceptance is still pending; this page does not announce a live credential service.

Read the setup guideDiscuss a pilot invitation
01 / KEEP

Import deliberately

Choose a vault and submit a credential through the trusted browser or protected CLI input.

02 / ALLOW

Approve a receiver

Give an agent a named principal, a limited grant and an explicitly approved device.

03 / WITHDRAW

Revoke future access

Stop new VaultPerch deliveries. Rotate the provider credential separately if it may have been exposed.

A useful first release.

The invited pilot targets verified email and password onboarding, vault and principal management, credential import, approved receiver enrollment, and revocation. Availability will follow acceptance of those journeys.

The first CLI configuration is macOS with Node.js 24 and a native Keychain helper. An explicitly configured protected service-account directory is also planned for that tested configuration. Released installation artifacts are pending.

Linux, hosted MCP and native HOS integration are future work. They are not offered by this pilot page.

Know who holds
the keys.

VaultPerch is a custodial service operated by CognitionHub.com Ltd. Its design encrypts stored credential values with per-vault keys wrapped by separate server-held keys. This is not zero-knowledge storage: a privileged operator or compromised server could gain access.

After delivery, a receiving process can copy or use the credential. Revocation stops future VaultPerch admission; it cannot recall a credential already delivered or revoke it at its provider.

Password reset uses the verified mailbox and invalidates owner sessions. A separate compromised-account choice also revokes agent enrollments. Losing the mailbox requires operator review of pre-existing continuity evidence; recovery may be refused if continuity cannot be established.

Loss of all applicable encryption and recovery keys makes retained credentials unrecoverable. Backup and restore acceptance is pending; no availability, recovery-time or retention SLA is offered here.

A small pilot.
A direct contact.

Questions, invitations and recovery support: support@vaultperch.com.

Report suspected exposure or a security defect privately to security@vaultperch.com. Include affected resource references and times, without passwords, tokens or credential values.