
lsPass
Local-first encrypted password manager for logins, notes, and API keys, using a SQLite vault sealed with Argon2id and XChaCha20-Poly1305; no cloud or…

Local-first encrypted password manager for logins, notes, and API keys, using a SQLite vault sealed with Argon2id and XChaCha20-Poly1305; no cloud or…

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

Authentication, authorization, traceability and auditability for SSH accesses.

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

Scalable API key server for issuing, verifying, and revoking credentials with token derivation for fine-grained capability tokens. Supports…

AzureAD/EntraID user activity reporter for blue teams. Input a suspicious user and time frame to receive a detailed report of user info, actions, and…

The Secure CommsOS™ for mission-critical operations

An open source, self-hosted implementation of the Tailscale control server

A tool for secrets management, encryption as a service, and privileged access management

Infisical is the open-source platform for secrets, certificates, and privileged access management.

The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™

The easiest, and most secure way to access and protect all of your infrastructure.

API-first identity and user management system for cloud-native applications. Handles login, registration, MFA, recovery, and profile management with…

Secure, private AI agent operating system with local encrypted storage, OAuth/SSO authentication, policy-based access control, and extensible…

Synapse: Matrix homeserver written in Python/Twisted.

Protect your SSH keys with your Mac's Secure Enclave

Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…