DV Enterprise

Product guide, documentation, and security architecture FAQ.

← Back to DV Enterprise

Enterprise credential security. Zero existence.

DVE keeps your credentials on your machines. PhantomKey never sees them. Neither does anyone else.

The problem

Enterprise password managers store your credentials on their servers. They promise encryption, but they hold the keys. A breach at the vendor means a breach of your vault — every login, every secret note, every API key your organization entrusted to them.

Even with strong encryption at rest, the architecture is the same: your decryption keys or key-wrapping material transits through infrastructure you do not control. Compliance questionnaires ask whether a third party can access your secrets. For most password managers, the honest answer is complicated.

The DVE difference

The cryptographic key that decrypts your credentials never leaves your endpoint.

DVE uses a local agent — running on each user's machine — to encrypt and decrypt. When you unlock DVE, key derivation and decryption happen on that device. The DVE backend stores encrypted envelopes it cannot open. PhantomKey operates the service, but we do not hold the keys to your vault.

This is not a marketing abstraction. It is how the product is built: agent-side encryption, opaque storage on the server, and an audit chain that records access without exposing credential content.

Three pillars

Zero Existence

Your keys never reach our servers — not during login, not during sync, not ever.

DVE's zero-existence model means PhantomKey cannot decrypt your credentials, even if compelled. We store ciphertext and chain metadata. We do not store passphrases, derived encryption keys, or plaintext secrets.

Tamper-Evident

Every credential access is recorded in a cryptographic audit chain that cannot be altered after the fact.

DVE maintains append-only hash chains for permission events, credential access, and operational audit. Each block links to the previous one. Modifying history breaks the chain — detectable during integrity verification and compliance export.

Enterprise-Ready

SSO (SAML, OIDC), SCIM provisioning, SIEM integration, compliance reporting, custom branding, and dedicated relay options for larger organizations.

DVE is built for teams that already run IdPs, SIEM platforms, and formal access reviews — not for consumer password storage with an admin panel bolted on.

Talk to us