EAS dev-tools · module

The secrets vault your stack already trusts.

Empire Secrets Vault is a self-hosted, client-side-encrypted secrets manager — Bitwarden-compatible at the core — that plugs straight into the EAS dev-tools suite you already run. SSO via your Authentik. Secret-injection into your CI and AI agents. Audited by the same audit you already buy.

Add to your suite Why not just Bitwarden?

Why a vault inside the suite — not another silo

The vault itself is a commodity. The integration is the product.

One SSO

Log in with the same Authentik that fronts your Sentinel, Mutator, and Lumen. No new identity silo.

Secrets that inject themselves

Your CI, agents, and apps pull secrets at runtime via the app-kit — no baking keys into env files.

Your sovereignty plane

Self-hosted on your infra (or ours, isolated). Client-side encrypted — the server only ever sees ciphertext.

Audited in place

The vault's event log flows into the EAS audit you already run — posture reporting on your own secrets, for free.

Pricing

Bundled

$0
included with EAS Platform All-In
  • Shared instance, per-org collections
  • SSO + audit included
  • Attach driver for the suite
In the All-In bundle

Add-on

$15
per seat / mo
  • Add to any single EAS product
  • Authentik SSO
  • Agent/CI secret-injection
  • Self-hosted + audit trail
Add to your suite

Dedicated instance

$99
flat / mo · enterprise
  • Isolated container per tenant
  • Physical DB separation
  • For regulated buyers
Get a dedicated instance

Bitwarden Teams is $4/seat and 1Password Business is $8/seat — and they're great if all you want is a vault. We charge a premium because you're not buying a vault, you're buying it wired into your suite: SSO, secret-injection, and audit you'd otherwise integrate yourself.

Security posture

ControlWhat we do
Encryption at restClient-side AES-256 per Bitwarden protocol — server sees only ciphertext
Master passwordCustomer-set, zero-knowledge — we cannot recover it (by design)
Admin surfaceArgon2-hashed token, never exposed publicly, behind Authentik SSO
BackupsNightly encrypted, off-host, restore-tested before go-live
Tenant isolationPer-org collections (API-enforced) or dedicated container ($99)
AuditVault event log shipped to your EAS audit module

Self-hosted, client-side encrypted, audited by the same EAS audit you already run. SOC2 is on the roadmap, not claimed today.