Overview

PentaVault is a security-first control plane for runtime secrets, project access, proxy tokens and audit visibility. It is built for AI-assisted development, where the goal is to give tools and agents the secrets they need at runtime while limiting how often plaintext secrets are exposed on developer machines.

Architecture

  1. Clients
    Next.js dashboard · Rust pv CLI
  2. API
    Fastify · Better Auth
  3. Storage
    PostgreSQL · Drizzle

A Next.js 16 dashboard and a Rust CLI talk to a Fastify API that handles authentication, encrypted secret storage, project access policies and runtime resolution, with PostgreSQL behind it.

Security model

  • Secrets are stored encrypted, and access is deny-by-default per project.
  • Every access is written to an audit log.
  • The CLI signs in with a device-code flow (pv login) and is read-only: list projects, environments and secrets, pull them, or pv run a process with secrets injected at runtime.

Testing

The dashboard runs lint, type checks and unit tests, with browser flows covered by Playwright (UI-only tests run against mock auth). The CLI has its own build, lint and test pipeline.