Vault Security & Access
Updated 2 July 2026
Vault items are encrypted when stored using industry-standard encryption. Access is restricted to authorised BugShield developers during active work on your site.
This article explains how Vault access is controlled and logged, plus what you should do to keep shared credentials safe and up to date.
Access logging
Every time a developer views or redeems a vault credential, the event is recorded in your site's activity log with a timestamp and the developer involved.
Your responsibilities
- Only store credentials you are authorised to share.
- Remove outdated credentials promptly.
- Never send passwords by email or chat.
Vault items belong to the site they are stored for. If you remove a site from your account, its vault items are deleted.