Skip to content
Metamynd
Platform Engine

Credential Vault

Encrypted-at-rest storage for the upstream credentials your agents need — released just-in-time, only to a gateway, only against a currently-active Action Passport.

Overview

What it does

The Credential Vault stores third-party operational credentials — API keys, upstream service secrets — encrypted at rest, and releases plaintext through exactly one path. That path requires two independent factors: a shared gateway-only token the agent's own client never holds, and a currently-active Action Passport bound to the specific action requesting the credential. The tenant a credential is released to is derived from that passport, never taken as caller input, so a misconfigured or compromised gateway process can't misroute — or be tricked into serving — another tenant's secret. Every access attempt, successful or refused, is written to the same evidence trail as every other governance decision; the plaintext itself never is.

Core Functions

Inside Credential Vault

The core functions this engine provides across the Trust Fabric.

AES-256-GCM at rest
One release path, gated on two factors
Tenant derived from the passport, never the caller
Every attempt audited, plaintext never logged
One platform

Credential Vault composes with the Trust Fabric

Every engine is independently useful and interoperates through one API-first Trust Fabric — so identity, evidence, policy, risk and certification stay consistent across your AI estate.

Explore more

Related engines

Evidence Engine

Signs every decision, batches them into a Merkle root, anchors it on Hedera, and lets anyone verify a record offline.

  • Ed25519-signed receipts
  • Merkle batching
  • HCS anchoring
  • Offline verification (magp-evidence)
View engine

Audit Engine

Turns the signed evidence into a reconstructable, regulator-ready record — with inclusion proofs against an anchored root.

  • Immutable audit / regulator log
  • Merkle inclusion proofs
  • Reason-code decision trail
  • Downloadable, offline-verifiable
View engine

Supervisory Access

A scoped, revocable seat for a regulator or supervisor — with a hash-chained log of everything they read.

  • Grant-based, time-bounded access
  • Scoped to decisions, controls or proofs
  • Hash-chained access log
  • Readable by the supervised organisation
View engine

See Credential Vault in action

Book a demo and see how the platform establishes trust across your AI systems.