Skip to content
Kutrion

kutrion --platform

One platform for secrets and access

A vault for every secret type, an audited broker for every session, and the team controls to run it safely — six parts that share one audit trail.

Vault

One vault for every kind of secret.

Store logins, SSH keys, API keys, environment files and secure notes in a vault organised by type — envelope-encrypted, never plaintext at rest, and built for how engineers actually work.

Learn more

Terminal

Every session brokered and audited.

Connect to any host — Linux over SSH or Windows over RDP — through an audited access broker. Access is injected just-in-time, decrypted in memory for the authorized session only, and written to a complete audit trail.

Learn more

Transfer

Managed file transfer on the same audited broker.

Move files between SFTP, FTP/FTPS, WebDAV and object storage through the broker that already holds the credentials. Ad-hoc copies, scheduled jobs and watched folders all run server-side, are governed by policy on the way through, and land on the same audit trail as every session.

Learn more

Teams & JIT access

Share access without losing control.

Shared team vaults with role-based access and just-in-time elevation. Onboard and offboard people in one place, and keep an attributable record of who had access to what, when.

Learn more

Browser extension

Your vault where you work.

Autofill logins and capture new credentials in Chrome and Firefox. The extension holds an encrypted copy of your vault on the device, so a fill is a local decrypt that works instantly and offline — sealed under a key your organization can withdraw, with every reveal still recorded.

Learn more

AI

Assistance that defaults to a self-hosted model.

AI help for the terminal and vault that defaults to a self-hosted model rather than a cloud one, and can be pointed at an endpoint on your own network. Terminal output and secrets do not reach a cloud model unless your organisation opts one in — the default and that opt-in are what keep them out.

Learn more

broker status

It all runs through one audited broker

No standing credentials on laptops. The broker decrypts in memory for an authorized session, then everything is on the record — across every part of the platform.

You & your team request access Kutrion broker › decrypt in memory › enforce policy + roles › just-in-time access › no plaintext at rest Hosts & secrets SSH · DBs · APIs Tamper-evident audit every access recorded