- 01Encrypts plaintext secrets for all CLI tools.
- 02Human in the loop for all authenticated tool use
- 03Security at the layer that counts: where tools are installed
Before Automic Vault
“Helpful” agents take dangerous shortcuts.
After Automic Vault
Plaintext secrets: detected, encrypted and gated.
Encrypting secrets is not enough
Human Approval Required
Encrypting secrets is only half of it when those secrets can be used for sensitive actions.
Automic Vault doesn’t just protect your secrets; it gates use of those secrets.
Adjust access granularly. One rule for you and one rule for agents.
Every secret use is restricted by default. Relax the gate only for the code-signed executable you name.
- Read only
- Auto-approve safe queries without granting write access.
- Full access
- Always approve direct
ghaccess only for a named calling app, such as Terminal.app.
Every secret use is logged.
Approved or denied, automatic or manual: every request leaves a local record with the launcher, key, command, working directory, and decision.
- Decision
- Launcher
- Requested key
- Working directory
Continuous monitoring of threats to your developer environments
Automic Vault monitors developer tools across all ecosystems. New threats are flagged instantly, with clear steps to mitigate each finding.
Free and open source.
Automic Vault costs nothing, but if you want additional security, the optional iPhone app is a paid subscription that moves approval gates off the computer running the commands and onto your phone, where no agents or malware can intercept them.