Security
Keys, Vault, Security Center, and Assignments — credentials, secrets, and the audit trail around both.
Credentials, secrets, and the audit trail around both.
Keys — /keys
Central registry for every SSH key in the fleet — which servers each key is assigned to, which key is the management key vs. a per-user assignment (shown as separate columns, since a key can be both at once), rotation history, and a fleet-wide authorized_keys scan that flags orphaned or unexpectedly-present keys on a live server.
Vault — /vault
Encrypted storage for anything that isn't an SSH key — service-account passwords, Wi-Fi credentials, license keys, API tokens. Entries can be scoped to a folder/category, and deleting one that's actively referenced elsewhere triggers a typed-confirmation warning first.
Security Center — /security
Admin, AI Assist. Fleet-wide vulnerability posture — scheduled security scans, CVE re-checks against installed packages (via osv.dev), and an AI-written analysis of scan findings in plain language.
Assignments — /assignments
Admin. Who can log in as which Linux/Windows user on which server — the join table between people and access, viewed and edited from one screen instead of hunting through each server's own credential list.
Credentials
Admin, sub-feature of Servers. A per-server secret vault for anything beyond the SSH management key — local Linux user passwords, database/web/application/service credentials. Reached from a "Credentials" tab on each server's detail view.
- Password rotation generates a new value and applies it live over SSH (
chpasswdfor Linux,Set-ADAccountPasswordfor domain accounts) before archiving the old one — if the live apply fails, nothing is archived and the old credential stays valid - Verify-against-live-server checks the stored password still actually works, catching drift before it locks someone out
- Every reveal, copy, create, update, rotate, and delete is audit-logged