Obsidian gives you a second brain.VaultGuard makes it your company’s.

Share your vault safely with granular permissions and audit logs, put any AI on it, and scale it to your whole team.

Free to self host. Open code you can audit. Nothing to migrate.

The Solo Ceiling

A second brain is a superpower. But it was built for one.

You built something brilliant in Obsidian. Fast, linked, alive. Then you tried to grow it, and you hit the ceiling.

The team cannot get in. There is no safe way to share a vault, so your best knowledge stays on one laptop.
The AI cannot get in. Point a model at raw notes and it chokes, or it reads the whole library to answer one question, and the bill arrives.

You could build a real one from scratch. Learn retrieval, stand up a database, wire five tools together, spend six months, then train everyone on a system they never asked for. Most teams start, stall, and go back to the wiki nobody opens.

So you are stuck between a tool that will not scale and a project that will not end.

It turns your vault into the company brain.

One living knowledge base that your whole team, and every AI you use, can think with. Not a filing cabinet where documents go to die. Not a six month build. It is the second brain your best people already love, grown up to run the company.

Shared
so everyone thinks together.
Secure
so you can open it up without opening it to everyone.
Ready for AI
so your models finally know what your company knows.

See how it works

See it run

The whole thing, end to end.

Create the organization, invite a teammate, install the plugin, then watch the same note change shape for an admin and for a viewer, including what that file looks like opened outside Obsidian.

Recorded in VaultGuard Cloud and in Obsidian. English captions are available from the player controls.

An upgrade, not a project

You can be live this afternoon.

1

Install on your vault.

No migration, no moving day. VaultGuard builds on the Obsidian you already run.

2

Answer five questions.

Sharing, permissions, and your company knowledge base go live in minutes.

3

Open the gate.

Connect any AI through one gateway. It is optimized, it respects permissions, and every visit is logged.

Open the step-by-step setup guide

Follow the verified setup flow from installation through the first protected sync.

Everything Obsidian was missing to run a company.

Safe to share.

Your notes are encrypted on your device before they ever sync, with per file permissions. Open your vault to the team without opening it to everyone. When someone leaves, their access is cut and the keys are rotated.

The gatehouse.

Connect any AI through one gate. Claude works out of the box, and any MCP tool like Claude Code, Cursor, or Claudian plugs into the same gate. Each one sees only what the person asking is allowed to see, and every visit is logged.

The archivist.

Your AI reads the right page, not the whole library. That is up to 90 percent fewer tokens for the same answer.

The ready hall.

Templates, presets, and a setup wizard, so your team can start working the day you turn it on.

The watchtower.

See every sync, share, and permission change, plus who read what through the server. Audit ready at any moment.

Works offline.

Your vault lives on your machine, encrypted, and syncs when you are back.

The permission map.

See who can open what as a map, not a spreadsheet.

AES 256 GCM encryption, on your disk and in the cloud. It is still just markdown underneath, yours to export any time.

The plates

The whole system, drawn.

Twelve engraved plates for the twelve parts of it. Nothing here is new — it is the same system the rest of this page describes, in the form it is easiest to see.

A readable record passes through a lock and leaves as a cipher record.

Encrypted on your device.

Your notes are encrypted on your device before they ever sync.

A carved permission matrix grants one explicit cell with a key.

Permission per file.

Access is granted file by file, not with one switch for the whole vault.

Three engraved member records connect to one explicit governance grant.

Open to the team.

Open your vault to the team without opening it to everyone.

Two records exchange through an engraved guard shield.

A pointer, not a key.

A share link points a teammate at a file they can already open.

Two engraved repositories exchange verified records through a seal.

Sync through the seal.

Your machine and the server exchange verified records, sealed both ways.

An engraved key passes through a renewal ring above a measured lease term.

Works offline.

Your vault lives on your machine, encrypted, and syncs when you are back.

An engraved ledger records events beside a governance watchtower.

The watchtower.

Every sync, share, and permission change is written down.

A robot agent crosses a gate only through a permission seal.

One gate for every agent.

Connect any AI through one gate, and every visit is logged.

A sparse two-lobe star-chart brain drawn from connected dots.

The page, not the library.

Your AI reads the right page, not the whole library.

A labelled archive paired with an engraved history return.

Recovery, in the app.

Invites, permission changes, and recovery flows all happen inside Obsidian.

An engraved citadel stands on a basalt foundation with a lit doorway.

Or run it yourself.

Self host the source available Community edition on your own AWS.

An engraved guard shield protects a ward on warm paper.

One boundary.

Encryption, permissions, and the record, drawn as a single shield.

We built this because we needed it.

VaultGuard started as an internal project. We were a small team running our whole company on Obsidian, and we hit the same wall you did. We could not share it safely, and our AI bill kept climbing. We did not want to move to Notion, and we did not want to spend half a year building a knowledge base from scratch. So we built the upgrade, and we run our company on it every day. Everything on this page, we use ourselves. Now you can too.

Start free. Grow when your team does.

Pay monthly, or choose yearly billing and save 25%.

Community

Freehost it yourself

The full plugin and server, source available. Deploy the encrypted sync stack on your own AWS with Terraform.

  • Up to 100 users, no per seat licensing
  • The same encryption as Cloud
  • Per file permissions
  • The in Obsidian admin
  • Open code, fair code license
Get it on GitHub

Enterprise

Customlet us talk

Dedicated infrastructure, sized to you, and the compliance story your security officer will sign off on.

  • Scale beyond the 100 user Pro tier
  • 1 TB storage
  • Single sign on
  • Dedicated infrastructure
  • Compliance evidence
  • Priority support
Contact sales

Every plan keeps your data in plain markdown. Leave whenever you like and take everything.


The honest answers.

Yes. It is your markdown, and it stays that way. Export any time and you have ordinary .md files. Stop paying us and you still have everything.

We are straight with you: it is not zero-knowledge. Your notes are encrypted on your device before they sync and stay encrypted at rest while Obsidian is active, and we never keep plaintext copies of your files. Encryption is server-managed, so the backend can handle your keys to run sync, sharing, and offboarding, and it can see basic metadata like filenames, paths, sizes, versions. Prefer to hold it all yourself? Self host, and the whole stack runs in your own AWS.

Your notes are encrypted on disk the moment you save them. Large files over 7 MB sit in a plaintext-pending state just long enough to confirm their encrypted copy uploaded, so a dropped sync can never leave your only copy stranded as unreadable ciphertext.

Up to 25 MB per file on Cloud, and when you self host, whatever configured file-size limit you set.

No. VaultGuard installs on the Obsidian vault you already have. Nothing moves.

Yes. Your vault lives locally and syncs when you are back online.

The moment you hit revoke, their server access is gone. Signed in devices sign out within a minute of being online, and the vault keys are rotated so the old key is useless. Anything already exported is out in the world and no tool can pull it back, and we will not pretend otherwise.

Claude works natively, with your own Anthropic key or Claude subscription. Beyond that, any MCP compatible tool plugs in, like Claude Code, Cursor, or Claudian. All through one gate that checks permissions and logs every visit.

An afternoon. The setup guide walks through the whole verified flow.

Read the docs

Make your whole company think together. By this evening.

Keep the tool you love. Give it to your team. Put any AI on it.

Free to self host. Nothing new to learn. Your data stays yours.