Credentials belong with the subscription
Store logins, API keys, recovery codes and related authentication details beside the subscription they unlock. Saved secrets are encrypted before storage and listed masked, so a workspace can organize access without turning every list into a plaintext password list.
Subment is not a zero-knowledge service: it can decrypt a secret when an authorized person requests it. That is how it supports controlled reveals and generates TOTP codes.
Give the right people the right level of access
Workspace membership and per-subscription permissions set the boundary. View, Use and Manage access let teams decide who can see a subscription, use its sign-in information or manage it. Permissions are checked on the server for each request.
Revealing or copying a login requires a recent sign-in confirmation and is recorded in the workspace activity log. Exports do not include passwords, keys or 2FA codes.
A better record of shared access
When access lives in a shared workspace, owners can see who has access and remove it when responsibilities change. For shared accounts, Subment also keeps the subscription, members and TOTP access in one place.
Read the Security page for the implemented protections and their limits.