ASL Vault is a credential store built around one deliberate split: the key material that locks a value away and the key material that opens it are two different things, and only one of them is ever needed to put something in. Adding a new credential, or replacing an old one, works while the vault is locked.
Reading a value requires your passphrase, which is never stored anywhere and is unlocked only into memory for as long as you keep the vault open. So loading the vault is never a moment of exposure: you can file forty credentials into a locked vault and nothing in that process is ever able to read one back — not the person doing it, not the job doing it, not anything watching it.
Writing is reserved for the owner's credential, deliberately. An earlier version let any registered application write, which meant a single compromised application could quietly overwrite a more important credential with a value of its choosing; that was found in an August 2026 review and closed the same day.
Today applications read, they never write. Anything you hand the owner credential to can file and rotate entries while the vault stays locked and still cannot decrypt a single one — but it can also delete entries, so treat that credential as the powerful thing it is.
Day to day you work from an inventory that stays readable while the vault is locked: every entry's name, category, description, who filed it, when it was created and when it was last replaced. You can audit what you are holding, hand a colleague a list, and confirm a rotation happened without ever unlocking anything.
Values themselves are shown one at a time, on request, only while the vault is open, and every single reveal is written to the history. On the phone app a revealed value hides itself again after thirty seconds and the screen cannot be captured while it is showing.
Applications get their own credential and read only the entries they were granted. A permission is granted by name or by name prefix, so when you rotate a key the application that depends on it keeps working without you re-granting anything, and nothing is readable by default.
Asking for a value that was never granted returns exactly the same answer as asking for one that does not exist, so a stolen application credential cannot be used to discover which values it might be able to open. Be clear-eyed about the limit of that: the inventory itself — names, categories, descriptions and dates — is visible to any application you have registered, and the fact that the vault exists, whether it is locked, and how many entries it holds are visible to anything that can reach it at all.
Grants control what can be opened, not what can be seen listed. The history is append-only and chained, so it is tamper-evident rather than merely long. Every add, replacement, reveal, deletion, lock, unlock, failed unlock attempt, application registration and permission change goes in.
The chain is re-checked from the very first entry each time you look at it, so a row that was edited or quietly deleted is reported as a break instead of being accepted as normal. Values never appear in the history — only the fact that access happened, by whom, and when.
The service answers only on the machine it runs on. Reaching it from anywhere else is something you add in front of it — a private connection you open, or a sign-in gate, which is how this company reaches its own. Because every value is individually sealed, a copy of the store is safe to keep somewhere else: the values in a copy are exactly as unreadable as the values in the original, and neither opens without your passphrase.
There is also a separate phone vault for people who want the same discipline in a pocket. It has no network permission at all — not a promise not to upload, but no ability to connect — no account, no telemetry, and no reset service. It seals itself the moment you leave the app, exports an encrypted backup through your phone's own file picker, and checks a backup's entire history before it will replace what you have.