Case study — encrypted credential sharing

Building a GDPR-compliant credential vault for European teams

How a solo build replaced spreadsheets and Slack threads with a secure, EU-hosted way to share credentials across a team.

48hto GDPR sign-off
Zeroplaintext credentials since launch
EUdata never leaves the region

The problem

My client sold to European teams who legally couldn't use most of the popular US-based credential managers — data residency requirements ruled them out entirely. Their own customers were stuck sharing passwords and API keys the way most teams still do: spreadsheets, Slack DMs, or one person who keys everything in by hand.

They needed a product that was both genuinely secure and provably EU-hosted, with nothing about the architecture left ambiguous for a compliance review.

What I built

SSH Vault is an encrypted credential-sharing platform built specifically for teams that can't take data residency on faith. Every credential is encrypted at rest, access is scoped and auditable, and the entire infrastructure runs on EU soil — no exceptions, no fallback to a US region under load.

The result is a tool a team can actually adopt without a six-month security review turning into a blocker.

Under the hood

Encryption, access control, and infrastructure were all designed around a single constraint: nothing sensitive ever touches a server outside the EU, and every access event is logged in a way an auditor can actually verify.

Role
End-to-end build — architecture, security design, deployment
Timeline
Solo build, iterative rollout
Stack
EU-hosted infrastructure, encrypted storage, audited access layer
Status
Live, in active use

The result

The client went from first conversation to GDPR sign-off in 48 hours, and there hasn't been a single plaintext credential stored since launch. Their customers get a tool that passes procurement review instead of getting stuck in it.

Need something built with data residency as a hard requirement, not an afterthought?

hello@nekena.com

Other projects