Skip to content

product hub

StretchVault

The StretchSuite secrets manager — store passwords, keys, and cards encrypted at rest, then govern, share, audit, and rotate them from one workspace.

StretchVault dashboard
StretchVault dashboard

What StretchVault is

StretchVault is the StretchSuite app for storing and governing secrets — passwords, secure notes, server credentials, API keys, and payment cards. It is the suite's enterprise secrets manager: the place your whole organization keeps sensitive values instead of spreadsheets, sticky notes, shared docs, or chat messages. If you have used 1Password Business or a similar tool, StretchVault will feel familiar, with the encryption, controlled sharing, security review, and rotation planning you expect from a business-grade credential platform.

Every secret you store is encrypted at rest with AES-256-GCM envelope encryption before it ever touches the database. StretchVault treats secret values as sensitive by default: list views, dashboards, exports, and reports show only metadata — title, username, URL, tags, strength, and exposure status — never the secret itself. Seeing a secret is a separate, deliberate action called a reveal, and every reveal is recorded in an access log.

Who it's for

StretchVault is built for teams that share access to systems: operations leads holding infrastructure logins, marketers juggling dozens of SaaS accounts, agencies safeguarding client credentials, and founders who need one governed place for everything sensitive. Owners and admins get full control; individual teammates get exactly the access they are granted, item by item.

Key capabilities

  • Vaults and items. Group related secrets into vaults (for example Shared Ops, Marketing SaaS, or Client Credentials). Each item has a type — Login, Secure note, Server, API key, or Payment card — plus fields like username, URL, tags, notes, and a 2FA flag.
  • Password & passphrase generator. Create cryptographically strong passwords (8–128 characters) or memorable passphrases (3–12 words) with a single click, tuned to your policy for length, character classes, and separators.
  • Strength analysis. As you save a secret, StretchVault scores its strength, estimates crack time, checks it against common-breach lists, and warns when it reuses your username, email, or site name.
  • Watchtower security review. Scan an entire vault for reused, weak, old, exposed, and no-2FA credentials, and get a single security score (0–100) with prioritized recommendations.
  • Breach-watch. A fast exposure scan that flags any item that is exposed, reused, weak, aging, or missing two-factor authentication.
  • Rotation planning. Generate a prioritized rotation plan — critical, high, medium, low — so you know exactly which credentials to change first and why.
  • Controlled sharing. Grant a specific person access to a single item at a chosen scope (view, reveal, or edit), with an optional expiry date, and revoke it at any time.
  • Folders & tags. Organize items inside a vault with folder paths and tags for fast retrieval.
  • Access log & audit history. See who revealed, shared, or changed what, and review saved Watchtower and rotation runs over time.
  • Health & encryption status. Confirm at a glance that encryption is configured and the security engine is online.

How it fits the suite

StretchVault runs on the same shared platform (api-core) as the rest of StretchSuite, so it inherits your organization, your teammates, and their roles automatically — there is no separate directory to maintain. Because credentials are scoped to your organization, the same StretchVault surface appears in the customer Workspace and in the Admin console with matching behavior. It complements the operational apps you already use: store the SMTP key that StretchMail sends through, the payment gateway credentials behind StretchShop, the database logins your StretchProjects team relies on, or the client account passwords your agency manages — all in one governed, audited place.

Where to start

If you are brand new, begin with Getting Started with StretchVault to learn the core concepts, then Creating Vaults and Adding Items to store your first credential. From there, turn on Watchtower to see how healthy your credentials are, use the Generator to replace weak passwords, and set up Sharing so your team can access what they need without anyone emailing a password again.

Was this helpful?

Help us improve this article

Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.