For regulated & security-first organizations

Enterprise-grade secrets management,
zero-knowledge by default.

SSO, role-based company vaults and an activity log, on top of an architecture where even your provider cannot read your vault contents. Deploy across thousands of seats without compromising on control.

Talk to Sales → Review the architecture
99.9%
Relay uptime SLA
24/7
Dedicated support

Everything IT needs to deploy with confidence

🔑

Single Sign-On

OIDC with any standards-compliant IdP — Okta, Microsoft Entra ID, Google Workspace, Ping, and more. Users sign in through the directory you already run.

⚙️

Provisioning & offboarding

Admins invite, assign and revoke access from the console, and revoking a member removes their vault keys. Automatic directory sync (SCIM) is on the roadmap, not shipped.

📊

Log export

Export the activity log as CSV or JSON from the admin console. Streaming to Splunk, Datadog or another SIEM is on the roadmap, not shipped.

🛂

Role-based access

Owner, admin and member roles across the organisation, and per-collection roles deciding who administers each company vault.

📜

Activity log

An exportable, filterable record of administrative and item events, with the actor, timestamp and source IP. Cryptographic tamper-evidence is on the roadmap, so this is an activity log rather than a tamper-proof audit trail.

🧬

Post-quantum crypto

Hybrid post-quantum key exchange protects shared vault keys against harvest-now-decrypt-later attacks — uncommon among password managers.

📋

Custom policies

Enforce master password strength, session timeouts, device trust, export controls, and IP allow-lists across the org.

🏢

Shared company vaults

Structured, permissioned vaults for teams and departments. Admins manage collections and access from the console; members see and open only the collections they've been granted, from their own vault.

🤝

Dedicated support

A named account team, priority response SLA, onboarding assistance, and a security questionnaire fast-track.

Central control without central risk

Most enterprise password managers ask you to trust that they won't look. Walilock is built so they can't. Admins manage identity, policy, and entitlements — but vault contents stay end-to-end encrypted and invisible to admins and to Walilock alike.

How the cryptography works →
🔒

Admins manage access, not secrets

Provisioning, roles, and policy — never the plaintext inside member vaults.

🛡

Breach-resilient by design

A compromise of the relay or an admin account exposes ciphertext only.

🌐

Local-first performance

Vaults work offline and decrypt on-device — no latency, no single point of failure.

📦

Data portability

Export everything in open formats. No lock-in, ever.

Bring zero-knowledge security to your org

Talk to our team about a pilot, security review, or volume pricing. We'll fast-track your questionnaire.

Contact Sales → Admin sign-in