What you can store
Payment cards are not stored. Paying for something works through a connected wallet and a one-time card per purchase, and every purchase asks you first.
How it stays safe
- You enter it, once. Items are added in Settings or on a sign-in page inside Henry. Editing means entering the value again; Henry never shows a stored value back, only a hint such as the last four characters.
- The model never has it. Logins are typed by a background worker while the model is paused. API keys are inserted at the network edge and scrubbed from what comes back. A page or an email cannot trick Henry into reading a stored value, because nothing Henry can read has it.
- Bound to you. Each item is encrypted under your workspace’s key and tied to your account. A copy of the stored data is useless to anyone else, including your teammates and Henry’s staff.
- Only where you said. A login for one site is refused on any other. A key for one host is refused on any other. The check happens before the item is opened.
- Every use is recorded. The item’s activity shows when it was used, on which site or host, and by whom, and any refusal with the reason.
- Revoke any time. Revoking or deleting an item stops every use immediately. Workspace admins can also switch off the Vault for everyone; stored items are kept but nothing can use them.
Sharing with your team
Workspace owners and admins can mark a login or key as shared with the team and pick which members may use it. Members use a shared item inside Henry the same way they use their own; they cannot read it, export it, or use it on another site. Admins can change the list or stop sharing at any point, and every use is recorded against the member who used it.Scheduled tasks
A scheduled task can use an API key only when you grant that key to the task when you activate it. Logins and identity items are used in conversations only. Temporary approvals you give in a conversation (“allow for this conversation”, “allow for 24 hours”) never carry over to a scheduled task.Limits
- The Vault is turned on per workspace. Ask your workspace admin if you do not see it.
- One login per site per person.
- Preview environments cannot open the Vault.