Documentation
The zero-trust access model
Why every request is evaluated on its own merits, regardless of network or prior session.
No implicit trust
KosheVault does not treat network location or a long-lived session as sufficient proof of authorization. Every vault operation is evaluated against current identity, device posture, and policy at the time of the request.
Least-privilege by default
New members start with no vault access. Access is granted explicitly, per vault, and is visible in People & access at all times. There is no organization-wide "everyone" vault by default.
Continuous verification
Sessions, devices, and API keys can all be reviewed and revoked independently from Settings, Devices, and API management — without requiring a password reset or affecting other access a member holds.