Every business owner asks it eventually, usually after a near miss. Someone left, someone got phished, someone could not reach an account on a Friday afternoon.

Where are we supposed to keep these passwords?

It is a fair question and it has a bad reputation, because every answer you find is a variation of the same thing: a better box to put them in. Here is the case for a different answer, and the honest trade-offs of each option along the way.

Keep the list out of anything that can be read

Start with what most companies do today, because it is where the risk actually lives:

  • A spreadsheet or a document with logins and passwords.
  • A notebook in a drawer, offline “for safety”.
  • The browser on each laptop, remembering everything.
  • A chat thread or a mailbox where credentials were once sent.

They differ in convenience and not in risk. Each one is a readable object: whoever holds it, has everything in it. And reading one leaves no trace, so a leak announces itself only through the damage.

The first requirement for a real answer is therefore not “somewhere safer”. It is nowhere readable. In Inheriti® Business a credential is encrypted in your browser before it goes anywhere, then split into shares that are useless on their own.

A spreadsheet holding every login, next to a plan where the secret is encrypted in the browser and split into shares across storage layers
The answer is not a place. It is nowhere whole, reachable only by the people you named.

Give people access without leaving the password in a document

The second requirement is the one that makes the spreadsheet survive every security policy: people need to actually work.

A shared vault solves that by handing out the secret, which is why it drifts. The password ends up in a personal manager, a screenshot, a chat with a contractor.

Access here is not a file you pass around. A member opens the secret inside Inheriti® Business, and their access is checked against their team membership at the moment they open it. Where it matters you can require other members to approve first, and every opening is recorded.

Let access end when someone leaves

Ask any owner what happens when someone leaves and you get the same shrug. The mailbox gets closed. The passwords stay in their head, and in whatever they exported.

When membership ends, access ends with it. Share records are marked invalid, and rotating a secret purges the old ciphertext, so a leftover share on a laptop that walked out of the door is inert: it cannot be authorised and it cannot be served.

See who opened what, without asking around

This is the part no file, vault or notebook can offer.

Every request, approval and reveal lands in your organisation’s audit trail, with the person, the role, the time and the plan. When a client, an auditor or an incident asks who opened what, the answer is a record and not a recollection.

Not even the provider can open it

Every option on the list eventually needs one more question: what if the place I put them gets breached?

The shares are spread so that no single location holds enough to reconstruct anything, and that includes us. The organisation key is derived in your browser and never reaches our servers. A reveal needs an authorised member of the right team at that moment, the organisation key, the distributed shares, and the approvals set on the plan.

So the answer to “where should we keep them” is not a place at all. It is nowhere whole, and reachable only by the people you named, in the way you decided.

What Inheriti® Business does about it, and why you need it

Every answer to “where should we keep them” is a better container. The useful answer is that the question has the wrong shape.

Inheriti® Business gives it a different one:

  • Nowhere whole. A credential is encrypted in your browser and split into shares held across multiple storage layers, so no single location holds enough.
  • Reachable only by the people you named, through team membership rather than a copy of the secret.
  • Revocable in practice, because ending membership marks share records invalid and rotation purges the old ciphertext.
  • Accountable, because every request, approval and reveal lands in your organisation’s audit trail.
  • Beyond our reach as well. The organisation key is derived on your device and never reaches our servers.

So the answer is not a place. It is a shape: nowhere complete, and reachable only in the way you decided.

Where to start this week

Pick the smallest useful step.

List the accounts the business cannot run without. Banking, domain registrar, cloud admin, payroll. Usually five to ten lines.

Note who can open each one today. Every line with one name is a single point of failure.

Move those first into a plan in Inheriti® Business, scoped to the team that needs them, with the approvals that fit. Then delete the readable copies, because the move is only finished when they are gone.

That is the whole answer to the question, and it fits in an afternoon. See how Inheriti® Business works.