Ukraine solidarity. Service offered free to Ukrainian businesses for as long as the war lasts. Request free access
HMAC-SHA-256 audit chain · integrity verified · Reproducible verification via public CLI command for the audit chain
Private beta · Zero-knowledge B2B vault

The European B2B vault
that CISOs
audit themselves.

Public AGPL-3.0 codebase. France-hosted. HMAC-SHA-256 audit chain verifiable any time, in a single command.

Adopted by technical teams and the public sector
OpenPGP
Encrypted in your browser
HMAC-SHA-256
Verifiable audit chain
AGPL-3.0
Public code, fork allowed

A stated trajectory, not a slogan

A stated trajectory, not a slogan
02 / Features

What no competitor combines today.

Five technical differentiators, verifiable in the codebase. Not a marketing promise but cryptographic artefacts your CISO can audit themselves.

Maximalist zero-knowledge

Your private key is never on our servers. Not even encrypted.

Most B2B vaults store the vault's private key, encrypted by your master password. ARDNTECH does not. The private key is generated and held exclusively in your browser (and on your hardware passkey, if you activate one). Our database contains no means of reconstructing it, even if it were to leak tomorrow.

[ 01 ]

Verifiable HMAC audit chain

Every action is chained with HMAC-SHA-256. Any retroactive tampering is detected in O(1). A public verification command lets your CISO confirm the integrity of the chain without trusting us.

[ 02 ]

Native multi-organisation

A personal account plus N memberships in organisations, each paid for by that organisation. Pivot-account model: you never pay out of pocket for your employers.

[ 03 ]

SSO on the free tier

SAML 2.0 and OIDC included on Free. No paid add-on. A team of three deserves the same protection as a mid-market group.

[ 04 ]

Metadata also encrypted

Secret names, types, URLs: everything is encrypted in the browser, just like the content itself. If our database leaks, the attacker cannot even see that you have a secret named "Production AWS". On a par with Passbolt v5.4+ on this point.

[ 05 ]

Self-hostable AGPL-3.0

Symfony 7.4 + MariaDB + Redis. Docker Compose in 5 minutes. No feature gated behind the SaaS: it is the same code.

03 / Sovereignty

Your secrets stay in France.

No CLOUD Act. No extra-European sub-processor. An infrastructure that we operate, and that you can audit line by line.

[ I ]

Paris hosting · 3 availability zones

A single region in the Paris area, operated by Scaleway. 3 availability zones, including one in a nuclear-bunker datacenter (DC3 Ile-de-France). ARDNTECH (the software) is not SecNumCloud-qualified; that qualification applies to the host, and Scaleway is on a SecNumCloud qualification trajectory.

FR / UE
[ II ]

French jurisdiction in the contract

French law, French court, standard DPA drafted in French. Your data does not leave European soil. DPO named, Art. 17/20 rights tooled.

Juridiction FR
[ III ]

Public AGPL-3.0 codebase

Server, clients, extensions: it is all on GitHub. No closed "Enterprise" module. If ARDNTECH were to disappear tomorrow, your deployment keeps running.

AGPL-3.0
[ IV ]

Full self-hosting

Hardened Docker image, Symfony binary, clear docs. Symfony 7.4 + MariaDB 11 + Redis stack. Air-gap supported. You stay sole master.

SELF-HOST
04 / Product

Four moves, verifiable line by line.

Demonstration on the demo instance. No promises: only what the code does.

app.aegirex.eu / vaults Step 01/04
P 1 membre
Personnel
128 entries
A 8 membres
ARDNTECH EI
64 entries
É 4 membres
Équipe DevOps
22 entries
C 12 membres
Clients
9 entries
A 1 membre
Archives
412 entries
+ New vault
Trust · pilot phase

What our first users tell us.

Five field reports gathered during the private beta. Contact details verifiable on request.

We manage client secrets across thirty engagements in parallel. Our No. 1 criterion is not price: it is that these secrets cannot be read by a third-party vendor, even under compulsion.
CIO · mid-sized consultancy 250 staff · Île-de-France
Professional secrecy forbids me a vault subject to the CLOUD Act. ARDNTECH is technically incapable of reading what is entrusted to it, and this is verifiable in the source code.
Partner · law firm 30 partners · Lyon
An association cannot afford an external CISO audit. The public AGPL-3.0 code gives us that audit for free, carried out continuously by the community.
Treasurer · non-profit association 12 employees · Paris
The HMAC audit chain is what our investors grasp in thirty seconds: we can prove the integrity of operations on secrets, with no prior trust required.
CTO · SaaS start-up 8 staff · Nantes
My clients' tax data does not leave the European Union. That is my only non-negotiable requirement, and ARDNTECH guarantees it both contractually and technically.
Chartered accountant partner 45 staff · Bordeaux
05 / Pricing

Security is not for sale, it is the baseline.

SSO, 2FA, passkeys, HMAC audit chain, GDPR export: everything is on the free tier. You pay for team governance, support and contractual guarantees.

Free
Free
Free for life · up to 3 users
To get started as a small team. Full security included.
Unlimited secrets and devices OpenPGP · SSO SAML / OIDC included TOTP, backup codes, passkeys HMAC audit chain visible · 30 days Full GDPR export, no friction
Team
Team
€4 / seat / month · annual
For teams of 4 or more.
6-role RBAC · signed invitations Team vaults and groups 90-day audit log Configurable SIEM export No commitment, monthly or annual
Recommended
Business
Business
€7 / seat / month · annual
Structured teams, unlimited seats, SCIM.
Everything in Team, no seat cap SCIM 2.0 · automated provisioning 1-year audit log · SIEM CEF/LEEF/OCSF 99.5% SLA · next business day email support Standard signed DPA
Enterprise
Enterprise
On request
Negotiated DPA, contractual SLA, long-term audit.
Self-hosted or dedicated SecNumCloud Negotiated SLA · phone support 5-year audit log · escrow opt-in Negotiated DPA · jurisdiction of choice Dedicated onboarding, training included
06 / Comparison

On the criteria that matter to a CISO.

Compared against the aggregate of US consumer-grade SaaS solutions. No competitor is named: internal marketing rule, you identify them on your own.

Comparative table of the main B2B password managers on European security and compliance criteria.
Criterion ARDNTECH US SaaS Shared spreadsheet
Zero-knowledge encryption -
France-exclusive hosting -
French jurisdiction in the contract In progress
Outside the CLOUD Act -
Publicly auditable code (AGPL-3.0) In progress -
Verifiable HMAC audit chain - -
Full self-hosting - -
SSO on the free tier In progress -
Recovery on loss designated successor vendor cloud account lost

Compared against the aggregate of US consumer-grade SaaS, public data 2026. Those products remain quality tools on their own terms; this table highlights the structural criteria for a regulated European CISO buyer.

07 / FAQ

The questions a CISO actually asks.

Technical answers, verifiable in the codebase. If an answer is not in the public docs or the repo, it is not true.

How does zero-knowledge work in ARDNTECH?

On sign-up, an OpenPGP keypair (X25519 / Ed25519) is generated locally by OpenPGP.js. The private key is encrypted by Argon2id (5 passes, 256 MiB, parallelism 4) with your master password. All crypto operations happen client-side. The server never sees plaintext.

Is ARDNTECH really open source?

Yes. The entire codebase (server, clients, extensions) is published under AGPL-3.0 on GitHub. No closed "Enterprise" module, no open-core. All SaaS features are available when self-hosting.

How do I verify the HMAC audit chain?

Run the public audit-chain verification CLI command on your instance. It re-reads the HMAC-SHA-256 chain and flags any tampering, even of a single entry. Reproducible by your CISO, pluggable into cron and automated monitoring.

What is the business model?

Four plans. Free for life up to 3 users (full security, SSO included). Team at €4/seat/month (annual) from 4 users, free for 12 months for non-profits, researchers and start-ups under 1 year old. Business at €7/seat/month (annual) with SCIM, 99.5% SLA, 1-year audit log. Enterprise on request (negotiated DPA, phone support, escrow opt-in).

What happens if I lose my master password?

This is the fundamental trade-off of zero-knowledge: without the key, neither ARDNTECH nor anyone else can recover your secrets. Two recovery mechanisms are provided: printable recovery codes generated at sign-up, and a designated-successor procedure using Shamir's Secret Sharing across N trusted parties you designate yourself.

Are you SecNumCloud-compatible?

The ARDNTECH architecture is compatible with SecNumCloud requirements (zero-knowledge, signed audit, French jurisdiction, traceability). Actual qualification requires (1) a host already SecNumCloud-qualified (Outscale, Cloud Temple), (2) a PASSI audit on the deployed instance, (3) governance documentation on the client side. We provide the crypto whitepaper and the technical evidence required for the dossier.

Ready to verify?

Take back control

The Free plan is free for life for independents and small teams of up to 3 users, with no credit card: your vault, your keys, your control. For larger teams, 7-day trial on the Team plan (also free for non-profits, researchers and start-ups). Or clone the code and self-host in five minutes.

France-hosted · SecNumCloud trajectory
AGPL-3.0 · public code on GitHub
French jurisdiction in the contract
HMAC audit chain verifiable from the CLI
Migration from spreadsheets, KeePass, and the legacy ecosystem