The vault your agent can use — and never read.
Every password, key, and private detail your agent needs to actually do things for you — sealed the moment you type it on your phone, carried encrypted to your own runtime, and locked there behind a password only you hold. Your agent works with your secrets the way a courier works with a sealed envelope: it can deliver it, it can't open it.
Why ThunderVault
Not a password manager your assistant peeks into. A sealed vault on hardware you own — where the agent can spend a credential without ever being shown it.
You enter a secret on your phone and it is encrypted on the device, before it goes anywhere. It travels sealed, lands on your own runtime, and is written to a vault that stays encrypted at rest. There is no point in that journey where your password exists in the clear — not on the wire, not on a server, not in a log.
Agents reference a secret by name, never by value. The runtime substitutes the real thing at the instant of use and lets it go. Your agent can log into a site or call an API on your behalf without the secret ever entering a chat log, a transcript, or a model prompt. It holds the envelope. It cannot open it.
Your personal side — identity, financial, medical, the passwords that are nobody's business — and your operational side, the keys and tokens your agent runs on. Two separate vaults, one password, one unlock. Simple for you, still compartmented underneath.
Unlock from your pocket with Face ID or a fingerprint — no typing a long password on a phone keyboard. The session lasts a set window and then the key is wiped from memory. Walk away and it locks itself behind you.
No vendor cloud. No sync service. No “trust us with your keys.” The vault lives on the machine you own, and the only copy of the password is the one in your head. We could not hand your secrets to anyone if we wanted to — we never have them.
What It Does
The phone is the door. The runtime is the safe. You manage it from your pocket; your agent uses it where it lives.
Open your agent's settings in ThunderCommo and add, change, or remove a credential — from anywhere. Sealed before it leaves your hand.
Your private data in one vault, your agent's operating keys in another. A grocery login and a production API key don't belong in the same drawer.
Your agent asks for “the bank password,” not the password itself. Substitution happens at the moment of use, then it's gone from memory.
A stored value only ever leaves the vault when you personally approve that specific request. Not the agent's judgment call — yours.
Change the master password and every entry in both vaults is re-encrypted under the new one. One action, whole vault current.
Channel tokens, provider keys, service credentials — swept off disk and into the vault, then wired into your agent at startup. Zero plaintext secrets, fleet-wide.
The credential lane answers only to devices that have authenticated to your runtime. Being able to reach your agent is not the same as being allowed to ask it for your secrets.
The key lives in memory for a limited window and is then wiped — no lingering unlocked state, no vault left open overnight.
An append-only record of every unlock and every read, written by the runtime itself — not by the agent. You can always see what was used and when.
The vault is encrypted with your password on your hardware. There is no recovery backdoor, no support override, no master key. That's the point.
How It Works
Three steps, once. After that your agent handles credentials the way a trusted assistant handles a sealed envelope.
During setup you choose the password that guards both vaults. It is never transmitted, never stored anywhere but in your head, and never recoverable by us — because we never hold it.
Open your agent's settings in ThunderCommo and add a credential. It's encrypted on your device, carried sealed to your own runtime, and written into the vault locked.
It signs in, calls the API, fills the form — using exactly what it needs, at the moment it needs it, without ever being shown the value. Approve an unlock with your face when it asks. That's the whole ritual.
Get It
ThunderVault is live today inside ThunderCommo and ThunderGate. Standalone apps for iPhone, iPad, Android and Mac are in development — drop your email and we'll bring you in.
Get Early AccessLive inside ThunderCommo & ThunderGate now · standalone apps in development · nothing ever stored on our infrastructure.