A place for credentials.
A scope for every agent.
VaultPerch is being built to let people and agent owners keep credentials in scoped vaults, approve receiving devices, and withdraw future access from one place.
Invitation-only. No billing during the pilot. Runtime acceptance is still pending; this page does not announce a live credential service.
Read the setup guideDiscuss a pilot invitationImport deliberately
Choose a vault and submit a credential through the trusted browser or protected CLI input.
Approve a receiver
Give an agent a named principal, a limited grant and an explicitly approved device.
Revoke future access
Stop new VaultPerch deliveries. Rotate the provider credential separately if it may have been exposed.
A useful first release.
The invited pilot targets verified email and password onboarding, vault and principal management, credential import, approved receiver enrollment, and revocation. Availability will follow acceptance of those journeys.
The first CLI configuration is macOS with Node.js 24 and a native Keychain helper. An explicitly configured protected service-account directory is also planned for that tested configuration. Released installation artifacts are pending.
Linux, hosted MCP and native HOS integration are future work. They are not offered by this pilot page.
Know who holds
the keys.
VaultPerch is a custodial service operated by CognitionHub.com Ltd. Its design encrypts stored credential values with per-vault keys wrapped by separate server-held keys. This is not zero-knowledge storage: a privileged operator or compromised server could gain access.
After delivery, a receiving process can copy or use the credential. Revocation stops future VaultPerch admission; it cannot recall a credential already delivered or revoke it at its provider.
Password reset uses the verified mailbox and invalidates owner sessions. A separate compromised-account choice also revokes agent enrollments. Losing the mailbox requires operator review of pre-existing continuity evidence; recovery may be refused if continuity cannot be established.
Loss of all applicable encryption and recovery keys makes retained credentials unrecoverable. Backup and restore acceptance is pending; no availability, recovery-time or retention SLA is offered here.
A small pilot.
A direct contact.
Questions, invitations and recovery support: support@vaultperch.com.
Report suspected exposure or a security defect privately to security@vaultperch.com. Include affected resource references and times, without passwords, tokens or credential values.
Privacy
This static website uses no third-party scripts, trackers or analytics and has no access to vault bindings or app authentication cookies. Hosting infrastructure receives ordinary request metadata such as network address and requested URL.
The intended app processes your email address, authentication records, vault and access metadata, encrypted credentials, and limited security/operational records to operate the service. Transactional email and hosting use Cloudflare. Operator access and encryption custody are described above. Contact support about privacy or deletion; exact app retention and deletion behavior will be recorded with the accepted release.
Never send credentials in support email. Correspondence is used to handle your request and any related security or recovery case.
Pilot terms
Operator: CognitionHub.com Ltd. Access is by invitation only, for authorized use of credentials you are entitled to manage. No billing, uptime SLA or guarantee of compatibility is offered for the pilot.
Use synthetic credentials until the operator confirms that the invited service and your configuration have passed acceptance. You remain responsible for provider-side permissions, credential rotation, receiving processes and independent mailbox access. Access may be suspended for abuse, exposure or recovery concerns. Contact support before entrusting a workflow that depends on uninterrupted availability.
These pilot terms do not remove rights that cannot lawfully be excluded. Changes to the offered service and material limits will be documented for invited users.