About
Sepulchre exists because the moment a secret has to pass between two people, most organisations fall back to the least secure channels they have.
We have vaults and secret managers for secrets at rest, and TLS for secrets moving between machines. But a vendor who needs production API keys gets them by email. A contractor gets a database password over chat. A new hire gets a signing certificate in a shared document that outlives three reorganisations. One-time-secret pastebins are an improvement, but they share one flaw: the company running the service can read everything. Using one just adds another party who can read your production keys.
Sepulchre removes that flaw. The credentials that pass through it can't be read by whoever operates it, and the operator can prove that with a policy file you can diff and a script you can run against the live system. The name is a sepulchre, a tomb: once something is sealed inside, the keeper of the tomb is not the one who opens it.
Licence
Sepulchre is licensed under Apache 2.0. It depends on no single vendor: Vault OSS, PostgreSQL, Traefik and Docker, deployable on any Linux host or on AWS, GCP or Hetzner. You run it on your own infrastructure.
Status
The proof of concept, both flows with the zero-knowledge property enforced, is complete, and all seven acceptance criteria are proven end to end. BYOK, OIDC single sign-on, a tamper-evident audit trail, Vault HA, runtime retrieval for CI and AI agents, and the SDKs and deployment modules have been built since. It has had an internal security review, not yet an independent third-party audit.
The source repository is not public yet. If you want to evaluate Sepulchre, run the proof, or talk about deploying it, get in touch.
Contact
Email sepulchre@melx.buzz for access, questions or a walkthrough. Sepulchre is built by Blake Medulan (LinkedIn).