Most passwords a team shares never really go away.
They sit in a chat thread, a notes app, a screenshot on someone's phone. Cask is for sharing passwords, keys, and anything else confidential with your team, in a way anyone can use, and where nothing lives longer than it should.
- A chat thread
- A screenshot
- A notes app
We built a vault for the team I lead.
Our own team kept its keys, settings, and shared logins scattered in exactly those places. So we built a vault.
Everything in it is locked, and nothing is kept in plain text. Before anyone sees a secret, the vault writes down who is looking and when. If it can't write that down, it doesn't show the secret. People who only need to use a secret can see it and copy it. People who manage secrets can only change the ones they added.
Check 1: You're signed in
Check 2: You're on the team
Check 3: You're allowed to see this one
Check 4: Your visit is written down
If the visit can't be written down, the envelope stays shut.
Now you see it
Then someone pressed copy.
The vault did its job. But every vault has the same edge, and it's the copy button. The moment a secret is copied, it goes straight back to the chat thread, the notes app, the screenshot.
Our own planning documents said so, and left the question open: people copy secrets into unsafe places, some secrets never get changed, and should a revealed secret hide itself again after a while? Nobody had answered it. That edge is where Cask starts.
The vault
After copy, nobody knows where it went.
The vault
After copy, nobody knows where it went.
A secret should have a lifetime.
In Cask, every secret you share has an age and an end. When you share something, you say who it's for and how long they need it: an hour, a week, until the project is over. When the time is up, it disappears from their view, unless someone decides to renew it.
Kept until someone remembers to delete it.
Renewed for another week
Gone
A secret that nobody renews was probably a secret nobody needed.
The design team can see this for one day. After that, it disappears unless you renew it.
No training needed.
Many of the people building products today didn't come from software. They came in because AI made building possible for them. They shouldn't have to learn what an environment variable is to share one safely.
So Cask speaks plainly. Who can see this. How long it lives. Who has looked at it. Anyone should know what to do the moment they open it.
- What
- The login for our payment account
- Who
- The design team
- For how long
- Two days
- Why
- Setting up the checkout page
When someone leaves.
The hardest day for a team's secrets is the day a person leaves. Usually nobody knows everything they could see, so nothing gets changed, or everything does in a panic.
Cask can show every secret that person had access to, and turn it into a short checklist of what to change, so the job actually gets finished.
Leaving: a teammate
- Payment account login(changed)
- Email service key(changed)
- Office Wi-Fi(changed)
- Social media login(not changed yet)
- Hosting account(not changed yet)
3 of 5 changed
And for someone outside the team, a freelancer or a client, there's a link that opens once and then stops working.
Here's the login you asked for
This link has already been used.
Not only for engineers' keys.
It started with keys and logins, because that's what an engineering team shares. But every team has things only some people should see: bank details, contracts, access codes, the recovery codes for an account everyone depends on. Cask is for all of it.
Share what's needed, for as long as it's needed. Then let it go.