Layer 7 ยท Data & Secrets

CyVault

Per-tenant HKDF key derivation. KEK never on disk. The compromise of one tenant can never decrypt another.

CyVault

CyVault is a credential vault built on HashiCorp Vault Raft 3-node + Transit envelope encryption. Per-tenant keys derived via HKDF โ€” a leak of one tenant's derived key never compromises another. The Key Encryption Key (KEK) lives only in Vault Transit โ€” never on disk, never in environment variables, never in memory longer than needed.

Gallery

See Cyvault in action.

Use Cases

Where CyVault wins.

1

Multi-tenant credential isolation

Each tenant gets HKDF-derived keys. A compromise of one tenant cannot decrypt another. Master key stays in Vault Transit, never touches disk.

2

Provider credential encryption

Cloud provider passwords (AWS, Azure, GCP) encrypted at rest per-tenant. Vault Transit Phase 3 promoted in production.

3

VDI session ticket encryption

Every CyDusk ticket wrapped with AES-256-GCM before Redis persist. Closes the plaintext-credential vulnerability that most VDI brokers ship with.

4

Session recording envelope encryption

Per-session DEK wrapped via Vault Transit. Recordings cryptographically tied to session metadata, decryption requires Vault access.

5

Zero-downtime key rotation

Rotate KEK; old DEKs still decrypt. Background re-encrypt without taking the system offline.

6

HashiCorp Vault Enterprise replacement

Built on Vault Raft + Transit; integrated with the rest of CyMesh. No separate vault product to deploy and operate.

Key Capabilities

What's inside.

๐Ÿงฌ

Per-tenant HKDF derivation

Tenant ID + master key โ†’ derived key. No cross-tenant blast radius.

๐Ÿ’Ž

Vault Transit envelope

KEK never on disk, never in env. Only Vault Transit knows the master.

๐Ÿ”„

Zero-downtime key rotation

Rotate KEK; old DEKs still decrypt. Background re-encrypt without downtime.

๐Ÿฐ

Raft 3-node HA

HashiCorp Vault foundation with 3-node Raft consensus for high availability.

๐Ÿ“œ

Forensic audit trail

Every secret access logged with actor, intent, justification. Immutable, 365-day retention.

๐Ÿ”Œ

JIT secret injection

Secrets injected into the session, never returned to the caller as plaintext.

vs competition: Replaces HashiCorp Vault Enterprise + custom KMS integration. Per-tenant HKDF closes the blast-radius vulnerability of single-master-key designs.
Full battle card โ†’

Ready to see CyVault in action?

30-day proof of concept on two idle servers. We bring the SE. You bring the use case.