Duckday

Credentials

The password is shared,
with a record of who looked.

Company credentials — the bank portal, the PEC, the supplier login — live in lists shared with the people, the roles or the permissions you choose. The secret is encrypted through a dedicated vault, revealed only on demand, and every reveal lands on the security log with a name and a time.

Duckday — credenziali

Credentials live in shared lists.

A credential belongs to a list, and a list is shared with named people, with roles, or with a permission. Whoever leaves the list loses the access.

One list, shared with two roles and one named person.

The secret is encrypted in a dedicated vault.

The secret passes through a dedicated vault engine before it is stored and is decrypted server-side only when someone with access asks to reveal it. It never sits readable at rest.

The reveal: on demand, decrypted server-side, for whoever holds the list.

Every reveal has a name and a time.

Opening a credential is a security event on the log. When a person leaves or a supplier is dropped, you know which secrets were seen, by whom and when —

The security log filtered on one credential: every reveal, named and dated.

New passwords are generated for you.

A new credential comes with a generated password, so the one that protects the bank portal is not the one that protects everything else. Full visibility over every list is its own permission, separate from ordinary administration.

A new credential with a generated password, in the list it belongs to.

Everything it does

  • Shared credential listsGroup logins into lists with a link and notes; a credential can sit in several lists, one personal by default.
  • Granular access sharingShare a list by person, role or a held permission; only the owner edits or deletes it.
  • Encrypted, audited vaultSecrets encrypted, a separate full-visibility permission, reveal on demand and every access logged.
  • Password generation and quick copyGenerate a secure 12-character password in one click and copy the username or password without revealing it.

Questions we actually get asked.

Is this a personal password manager?
No — it holds the company's shared credentials. Personal access to Duckday itself uses passkeys and two-factor authentication, which are a different mechanism in the same platform.
Who can see everything?
Only the holder of the full-visibility permission, which is granted separately. Everyone else sees the lists they own or were shared into, and nothing else.
What happens when someone leaves?
Remove them and the access is gone, because access lives on the list rather than in a copied file. The log still shows what they revealed while they had it.

Tell us how you work today.

There is nothing to prepare. Half an hour on how your company runs — who tracks the hours, how an invoice comes together, when you find out whether a commessa made money — and we tell you which modules would fix it and what a quote looks like.