Endpoint hygiene your security team would actually approve.
Disk cleanup and sensitive-file detection for macOS and Windows. File content never leaves the endpoint. That means no data-residency question and a small DPA surface. The compliance story, shipped as an architecture.
Not available yet. Vaulith for Teams is not something you can buy or deploy today. There is no admin console, no fleet management, and no seat provisioning: what ships today is the single-machine desktop app. This page exists so teams who need this can register interest and shape what gets built.
Signed & notarized · a standard installer · no kernel extension
What leaves the endpoint
Data that never leaves has no residency problem
The scanning engine runs on each machine and file content stays there. Most of what a vendor review must assess simply does not exist here.
No data-residency question
File content stays on the device it lives on. There is no region to pin and no cross-border transfer to assess.
Minimal DPA surface area
We process only account, licensing, and aggregate scan metrics. Counts and sizes, never content. Your legal team can finish reviewing that list.
Verifiable, not just asserted
The app makes a few narrow connections. Your team can watch every one with Little Snitch, Wireshark, or Activity Monitor. See how →
The sensitive-file shield: on-device checks flag documents that hold personally identifiable information (PII), protected health information, or financial account and routing numbers. Flagged files are excluded from bulk deletion by design. The claim and its disproving test →
A signed installer today. Fleet licensing still to build.
The desktop app ships as a signed, notarized installer. The org and seat groundwork sits in the backend, but nothing yet provisions, administers or reports on a fleet.
The installer Ships today
Standard installers, verified at launch by the OS.
- A standard signed installer, the same kind of artifact an MDM packages. We ship no deployment tooling, configuration profile, or managed rollout path of our own.
- macOS: Developer ID + Apple notarization, stapled and Gatekeeper-verified. Universal (Intel + Apple Silicon).
- Windows: Authenticode, CN=Vaulith LLC via Azure Trusted Signing.
- No kernel extension, no background agent. System files are always excluded from cleaning.
Volume licensing & seat pooling Not available yet
Backend groundwork only. There is nothing to provision, administer or buy.
- Pooled seats under one license key, with per-seat device limits. The schema, oversell-safe seat counter, and per-org isolation are implemented in the backend.
- The backend defines an active org seat as Pro-equivalent, superseding a member’s individual plan while active.
- Headless activation by license key is the intended path, so a device could take a seat without per-user OAuth. The activation call exists in the backend. Nothing in the installer uses it yet.
- Self-serve provisioning, an admin console, and invoicing for POs are not built.
Straight talk on status: the licensing core (orgs, pooled seats, device limits) is implemented in the backend, and that is the whole of it. No admin console, no provisioning flow, no fleet reporting, and no way to buy seats. We would rather show you the line than imply a console that isn’t shipped. If this is what your team needs, write to us and tell us what it has to do.
The procurement pack, ready to forward
Everything a security, IT, or GRC reviewer asks for about the desktop app that ships today. Answered truthfully, including what is still roadmap.
Security Whitepaper
Architecture-to-controls mapping: no-egress design, signing chain, recoverable deletion, minimal data, subprocessors, and roadmap.
Read online →Vendor Questionnaire
Pre-answered CAIQ / SIG-lite: data handling, encryption, access, build integrity, incident response, subprocessors. We’ll complete yours from this baseline.
Request a copy →DPA (draft template)
GDPR Art. 28 processor terms with a subprocessor annex. A draft pending legal review, not an executed agreement. Shared to start yours.
Request the draft →On certifications, plainly: Vaulith does not hold its own SOC 2. It has not yet had an independent penetration test. Both are on the roadmap. For the parts they run, our subprocessors are certified: Supabase holds SOC 2 and Stripe holds PCI DSS Level 1. We claim nothing Vaulith does not have.
Built by someone who reviewed tools like this
Vaulith is built by a founder with a security and risk background. The no-egress design, the recoverable safety model, and the minimal data posture come straight from that background. The product was designed to be the tool a security reviewer would approve.
Tell us what it would have to do
Vaulith for Teams is not available yet. Tell us your fleet size, your OS mix, and what this would have to do for you. We’ll send the whitepaper, complete your security questionnaire, and share the DPA draft, and what you need goes into what gets built.
Talk to us: register interest Not available yet · no seat checkout, self-serve or otherwise · support@vaulith.com