Built for AI environments and quantum threats, Agentic Vault delivers end-to-end encryption, policy-governed access, and a complete audit trail down to the individual secret.
SAN FRANCISCO — July 28, 2026 — C1 today launched Agentic Vault, a post-quantum secrets vault built into its identity platform. C1 governs every identity, then secures and manages the credentials used by users, agents, and service accounts. Agentic Vault prevents credential-driven breaches by putting secrets under the same identity and policy controls you already use for access. It also plants decoy credentials that fire an alert the moment anyone uses them. Every secret is least-privileged, just-in-time, and fully auditable, without multiplying vaults or expanding blast radius.
Every credential is a key to something. An API key, a database password, or a signing token is an identity's power to act, and most identities are no longer human. Traditional vaults were built for a person checking out a password now and then. At agent scale that leaves two bad options: grant broad access and widen the blast radius, or stand up a vault per credential and drown in sprawl. GitGuardian's State of Secrets Sprawl 2026 reported 28.65 million new secrets leaked on public GitHub in 2025, up 34% year over year, with leaked AI-service credentials up 81%.
The quantum threat makes this challenge even more urgent. On June 22, 2026, the White House signed an executive order directing federal agencies to migrate to post-quantum cryptography, explicitly naming the risk: credentials encrypted under today's standards can be harvested now and held for decryption once quantum computers reach sufficient scale. Organizations running legacy vaults are accumulating that exposure today.
Agentic Vault solves for these challenges. Every vault is built on zero knowledge architecture with MLS group cryptography, so credentials stored in C1 are protected against quantum decryption from day one. Every reveal is policy-checked at request time, so the access a person or agent receives is always right-sized to the moment. Rather than relying on manual scripts or human intervention, the vault natively handles end-to-end credential rotation, automatically provisioning, cycling, and destroying secrets at machine speed. Every read and rotation event is logged with full trust context: who, what, when, under which policy. Plus, there's a complete audit trail down to the individual secret for instant visibility without running a separate report.
"You have to control what agents have access to. And that starts at the credential, and credentials are about identity," said Alex Bovee, CEO and co-founder of C1. "The C1 Agentic Vault governs every secret and is built for humans and machine workloads."
Agentic Vault is built into C1's agentic control plane. Every credential follows the same request, approval, and audit path as any other access action in the platform. No separate governance system. No gaps in the loop. Ready for speed as AI adoption scales and improves security to prevent risks before they become incidents.
C1 customers are using Agentic Vault today. For more information, visit Agentic Vault or request a demo at c1.ai.
About C1#
C1 is the control plane for the agentic enterprise, empowering companies to adopt AI fearlessly. Our platform secures human and non-human identities, automates access, and accelerates AI adoption. With C1, the fastest path to AI adoption at scale is the governed path—giving organizations visibility and control without sacrificing security or slowing innovation. Companies such as Ramp, Zscaler, Instacart, and Brex trust C1 to power their agentic transformation.

