Security

Keys, Vault, Security Center, and Assignments — credentials, secrets, and the audit trail around both.

Credentials, secrets, and the audit trail around both.

Keys — /keys

Central registry for every SSH key in the fleet — which servers each key is assigned to, which key is the management key vs. a per-user assignment (shown as separate columns, since a key can be both at once), rotation history, and a fleet-wide authorized_keys scan that flags orphaned or unexpectedly-present keys on a live server.

Vault — /vault

Encrypted storage for anything that isn't an SSH key — service-account passwords, Wi-Fi credentials, license keys, API tokens. Entries can be scoped to a folder/category, and deleting one that's actively referenced elsewhere triggers a typed-confirmation warning first.

Security Center — /security

Admin, AI Assist. Fleet-wide vulnerability posture — scheduled security scans, CVE re-checks against installed packages (via osv.dev), and an AI-written analysis of scan findings in plain language.

Assignments — /assignments

Admin. Who can log in as which Linux/Windows user on which server — the join table between people and access, viewed and edited from one screen instead of hunting through each server's own credential list.

Credentials

Admin, sub-feature of Servers. A per-server secret vault for anything beyond the SSH management key — local Linux user passwords, database/web/application/service credentials. Reached from a "Credentials" tab on each server's detail view.

  • Password rotation generates a new value and applies it live over SSH (chpasswd for Linux, Set-ADAccountPassword for domain accounts) before archiving the old one — if the live apply fails, nothing is archived and the old credential stays valid
  • Verify-against-live-server checks the stored password still actually works, catching drift before it locks someone out
  • Every reveal, copy, create, update, rotate, and delete is audit-logged