Share your vault safely with granular permissions and audit logs, put any AI on it, and scale it to your whole team.
Free to self host. Open code you can audit. Nothing to migrate.
The Solo Ceiling
You built something brilliant in Obsidian. Fast, linked, alive. Then you tried to grow it, and you hit the ceiling.
You could build a real one from scratch. Learn retrieval, stand up a database, wire five tools together, spend six months, then train everyone on a system they never asked for. Most teams start, stall, and go back to the wiki nobody opens.
So you are stuck between a tool that will not scale and a project that will not end.
One living knowledge base that your whole team, and every AI you use, can think with. Not a filing cabinet where documents go to die. Not a six month build. It is the second brain your best people already love, grown up to run the company.
See it run
Create the organization, invite a teammate, install the plugin, then watch the same note change shape for an admin and for a viewer, including what that file looks like opened outside Obsidian.
An upgrade, not a project
No migration, no moving day. VaultGuard builds on the Obsidian you already run.
Sharing, permissions, and your company knowledge base go live in minutes.
Connect any AI through one gateway. It is optimized, it respects permissions, and every visit is logged.
Follow the verified setup flow from installation through the first protected sync.
Your notes are encrypted on your device before they ever sync, with per file permissions. Open your vault to the team without opening it to everyone. When someone leaves, their access is cut and the keys are rotated.
Connect any AI through one gate. Claude works out of the box, and any MCP tool like Claude Code, Cursor, or Claudian plugs into the same gate. Each one sees only what the person asking is allowed to see, and every visit is logged.
Your AI reads the right page, not the whole library. That is up to 90 percent fewer tokens for the same answer.
Templates, presets, and a setup wizard, so your team can start working the day you turn it on.
See every sync, share, and permission change, plus who read what through the server. Audit ready at any moment.
Your vault lives on your machine, encrypted, and syncs when you are back.
See who can open what as a map, not a spreadsheet.
AES 256 GCM encryption, on your disk and in the cloud. It is still just markdown underneath, yours to export any time.
Twelve engraved plates for the twelve parts of it. Nothing here is new — it is the same system the rest of this page describes, in the form it is easiest to see.
Your notes are encrypted on your device before they ever sync.
Access is granted file by file, not with one switch for the whole vault.
Open your vault to the team without opening it to everyone.
A share link points a teammate at a file they can already open.
Your machine and the server exchange verified records, sealed both ways.
Your vault lives on your machine, encrypted, and syncs when you are back.
Every sync, share, and permission change is written down.
Connect any AI through one gate, and every visit is logged.
Your AI reads the right page, not the whole library.
Invites, permission changes, and recovery flows all happen inside Obsidian.
Self host the source available Community edition on your own AWS.
Encryption, permissions, and the record, drawn as a single shield.
VaultGuard started as an internal project. We were a small team running our whole company on Obsidian, and we hit the same wall you did. We could not share it safely, and our AI bill kept climbing. We did not want to move to Notion, and we did not want to spend half a year building a knowledge base from scratch. So we built the upgrade, and we run our company on it every day. Everything on this page, we use ourselves. Now you can too.
Pay monthly, or choose yearly billing and save 25%.
The full plugin and server, source available. Deploy the encrypted sync stack on your own AWS with Terraform.
Yearly: €9 per user/month (25% off)
Managed cloud, no ops for you. Most teams start here.
Dedicated infrastructure, sized to you, and the compliance story your security officer will sign off on.
Every plan keeps your data in plain markdown. Leave whenever you like and take everything.
Yes. It is your markdown, and it stays that way. Export any time and you have ordinary .md files. Stop paying us and you still have everything.
We are straight with you: it is not zero-knowledge. Your notes are encrypted on your device before they sync and stay encrypted at rest while Obsidian is active, and we never keep plaintext copies of your files. Encryption is server-managed, so the backend can handle your keys to run sync, sharing, and offboarding, and it can see basic metadata like filenames, paths, sizes, versions. Prefer to hold it all yourself? Self host, and the whole stack runs in your own AWS.
Your notes are encrypted on disk the moment you save them. Large files over 7 MB sit in a plaintext-pending state just long enough to confirm their encrypted copy uploaded, so a dropped sync can never leave your only copy stranded as unreadable ciphertext.
Up to 25 MB per file on Cloud, and when you self host, whatever configured file-size limit you set.
No. VaultGuard installs on the Obsidian vault you already have. Nothing moves.
Yes. Your vault lives locally and syncs when you are back online.
The moment you hit revoke, their server access is gone. Signed in devices sign out within a minute of being online, and the vault keys are rotated so the old key is useless. Anything already exported is out in the world and no tool can pull it back, and we will not pretend otherwise.
Claude works natively, with your own Anthropic key or Claude subscription. Beyond that, any MCP compatible tool plugs in, like Claude Code, Cursor, or Claudian. All through one gate that checks permissions and logs every visit.
An afternoon. The setup guide walks through the whole verified flow.
Keep the tool you love. Give it to your team. Put any AI on it.
Free to self host. Nothing new to learn. Your data stays yours.