A zero-knowledge password manager for your team, on the same sign-in, the same admin, and the same bill as the rest of TATER. The secret fields - passwords, secure notes, API keys, card numbers, one-time-code seeds - are encrypted and decrypted in your browser, so the server holds only ciphertext for them and not even TATER's own AI tools can read them. Item titles, types and folders stay in cleartext so the list, search and sort work server-side. Stop paying a separate vendor for the vault your compliance program already assumes you have.
A full-featured team password manager - the capabilities you'd expect from a standalone product, folded into the suite you already run.
Encryption and decryption happen in your browser with a key derived from your master password. The server stores the secret fields as ciphertext only - TATER staff, the AI Analyst, and the MCP tools can't read your secrets, by design. To be precise about the boundary: item titles, types and folder names are stored in cleartext so listing and search work, so treat a title as a label others could read, not as somewhere to put a secret.
Keep passwords, secure notes, API secrets, payment cards, and identities in one organized vault - with folders, search, and favorites so the right entry is one keystroke away.
Keep the two-factor code with the login it belongs to - Vault generates the rolling 6-digit code right where you sign in, so that's one less app to juggle.
Generate strong passwords or human-readable passphrases with length and character controls, so every new credential is unique and hard to guess from the moment it's created.
Share a set of credentials with a group through a shared vault - scoped so the right team gets the right logins, and access is revocable the moment someone changes roles or leaves.
The organization retains escrowed access to vault data, so an offboarded, locked-out, or departed employee never takes critical credentials with them. Reclaim a user's vault as part of offboarding.
Surface weak, reused, and aging passwords across the vault. The analysis runs as counts your device computes and self-reports - so hygiene reporting never exposes the underlying secrets.
Move in from another manager, take an encrypted personal export with you, and let admins pull an inventory export for the record. A browser extension autofills logins where your team actually works.
A separate, more tightly controlled vault for sensitive documents and files - kept apart from day-to-day passwords, with its own access controls for the records that need them.
The same zero-knowledge vault opens in your phone's browser today, with the same passkey or passphrase unlock. A native Android shell for Intune line-of-business deployment is in development; iOS is planned after it. System-level autofill is not yet available on either — on mobile you copy from the vault rather than filling from the keyboard.
Hand a password or file to someone outside the organization through a link that expires after a set time or number of views. The decryption key travels in the link itself - never to the server - and the recipient needs no account.
TATER Vault is an add-on app at $4 per user / month (25-user organization minimum), on the same Entra ID sign-in as the rest of the platform - add it to any TATER subscription with no separate account or vendor. It's also bundled in at no extra cost with the $15/user/month Complete Platform. Enterprise and MSP volume discounts apply. TATER Send (above) is included - no separate license for external secret hand-offs.
Almost every framework expects credentials to be stored securely, shared deliberately, and reclaimed at offboarding. TATER Vault makes that real without a separate purchase, a separate login, or a separate admin console - the passwords live next to the controls, policies, and audits that reference them.