Skip to main content
Self-hostable · Built for DevOps teams

One login. One platform.
Your entire infrastructure.

Vaultex is the single pane of glass for servers, secrets, monitoring, automation, and team access — replacing spreadsheets, sticky notes, and scattered password managers.

AES-256-GCM vaultFull audit trailRBAC + 2FALive monitoring
vaultex · dashboard

Servers online

12/14

Avg uptime

99.7%

Secrets to rotate

3

Open alerts

1

Fleet health

live

Attention

  • SSL expiring on api.prod
  • edge-02 offline 4m
  • 2 weak credentials

Platform

Everything your team needs in one place

Modular by design — use what you need today, enable more as you grow.

Server Manager

Inventory every host — IP, OS, environment, tags, groups — with live status badges and bulk ops.

Encrypted Vault

SSH keys, DB passwords, and API secrets encrypted at rest. Reveal is permission-gated and fully audited.

Monitoring

Ping/HTTP/TCP checks, SSL expiry, incidents, alert rules, and maintenance windows that actually work at 3am.

Task Runner

Run approved commands over SSH from the UI with live output streaming, approvals, and cron schedules.

Port Map

Fleet-wide view of open ports with public/internal exposure flags for fast security reviews.

Locations

Document DCs and cloud regions, then see impact — which servers die if a site goes down.

Audit Log

Immutable trail of who did what, with before/after diffs. Export for compliance any time.

Integrations

Telegram, Slack, SMTP, Twilio, OpenRouter, Gemini — plug in alerts and AI without rewiring the core.

Team & RBAC

Granular permissions, custom roles, invitations, and 2FA — least privilege by default.

Workflow

Up and running in minutes

01

Sign in once

One identity for servers, vault, monitoring, and automation — with role-based access.

02

Map your fleet

Add servers, locations, ports, and credentials. Link secrets to the hosts that need them.

03

Stay ahead

Monitoring, alerts, scheduled tasks, and an AI assistant surface what needs attention today.

Security

Built for teams that can't afford a leak

Secrets never leave encrypted storage without a permission check. Every reveal, copy, and mutation is logged. Admins get a full console for roles, sessions, and system health.

  • Envelope encryption for vault fields
  • Defense-in-depth RBAC (middleware → action → service)
  • TOTP 2FA with recovery codes
  • Rate-limited auth and session revocation

Secure by design

AES-256-GCM secrets, Argon/bcrypt passwords, TOTP 2FA, scoped API keys.

Accountable

Every mutation and secret reveal is written to an immutable audit log.

Real-time where it matters

Live status boards, streaming task output, and notification badges.

Modular & extensible

Drop in modules and integration adapters without rearchitecting the platform.

Ready to unify your ops stack?

Sign in to manage infrastructure, secrets, and automation from a single secure control plane.