Zero-knowledge secrets for modern teams

Share access.Not exposure.

Shardbox keeps passwords, API keys, and developer secrets easy to find, safe to share, and impossible for us to read.

Client-side encryption
Personal + team vaults
Enterprise SSO ready
Search vaults and secrets
Acme Labs/Platform

Production

6 membersEncrypted

Stripe production

API key · 2m ago

AWS deploy role

Access key · Yesterday

Supabase service

Service role · Aug 28

Unlocked on this device

Plaintext keys never reach Shardbox servers.

Encrypted locallyKeys stay yoursZero knowledge
Order without compromise

Every secret has a place.Every person has a boundary.

Shardbox separates organization from access control, so your vault stays intuitive even as teams, environments, and credentials multiply.

A hierarchy that thinks like you do
Move from workspace to vault to nested folders without flattening everything into one endless list.
Share with people or teams
Grant a vault to one teammate or an entire engineering group. Everyone receives their own encrypted key envelope.
Find it without leaking it
Names, folders, URLs, tags, and custom fields stay encrypted. Search happens after your device unlocks them.
Organization without exposure

Find the right credential before the deploy finds the wrong one.

Build clear, nested categories inside each security boundary. Folder names and item metadata stay encrypted alongside the secret.

Nested foldersFlexible tagsLocal searchCustom fields

Acme Labs / Platform

Vault structure

18 secrets
Production8
Cloud infrastructure4
AWS deploy roleAccess key
Cloudflare APIToken
Data services3
Supabase serviceService role
Payments1
Stripe productionRestricted key
Zero means zero

Your server account opens a door. It never opens the vault.

Identity and encryption stay deliberately separate. Even complete access to the application database reveals ciphertext, public keys, and encrypted key envelopes—not the plaintext needed to use them.

01
Authenticate
WorkOS verifies who you are and which organizations you belong to.
02
Unlock locally
Your vault password and Account Secret unlock your private keys on your device.
03
Sync ciphertext
Supabase stores encrypted records and wrapped keys—not the material needed to open them.

Trusted client

Plaintext lives here

encrypts before upload

Ciphertext

Authenticated + versioned

syncs through

Supabase

Never receives vault keys

One identity, every workspace

Personal when it should be. Shared when it needs to be.

Keep one private vault, join multiple companies, and switch context without juggling accounts. Tenant ownership and access remain explicit.

WorkOS-powered organization switching
SAML and OIDC for enterprise customers
Teams, roles, and vault-level grants

Switch workspace

Your vaults

WorkOS verified
JB

Personal vault

Only you

AC

Acme Labs

12 members · Enterprise

NX

Northstar Studio

4 members

Teams are access shortcuts
Grant Engineering once; each member still gets an individual encrypted envelope.
Enterprise SSO stays optional
Paid tenants connect Okta, Microsoft Entra, Google Workspace, or any SAML IdP.
The important questions

Security should be explainable.

No hand-waving, no “military-grade” mystery. The trust boundary should be clear enough for every customer to challenge.

A better place for the keys that matter

Stop sharing secrets in places built for messages.

Give every developer the access they need, without giving the service provider a master key.

Create your vault