Cybersecurity, SaaS and Credential Management

LockYantra

Passwordless Credential and Secret Management Platform

LockYantra is a passwordless credential and secret management platform for individuals, teams and organisations. It allows users to store passwords, API keys, SSH keys, recovery codes, private notes and confidential documents in one place. Users can sign in through a secure magic link instead of using a traditional account password. The platform allows sensitive information to be shared with team members or clients. Access can be temporary or permanent and can be removed whenever required. LockYantra provides a more secure and organised way to handle important credentials and confidential information.

USAMarket
2 MonthsTimeline
3 DevelopersTeam
Cybersecurity, SaaS and Credential ManagementIndustry
LockYantra

Project Overview

LockYantra is a passwordless credential and secret management platform for individuals, teams and organisations. It allows users to store passwords, API keys, SSH keys, recovery codes, private notes and confidential documents in one place. Users can sign in through a secure magic link instead of using a traditional account password. The platform allows sensitive information to be shared with team members or clients. Access can be temporary or permanent and can be removed whenever required. LockYantra provides a more secure and organised way to handle important credentials and confidential information.

What We Built

We built a secure platform for managing and sharing credentials and confidential information. The work covered the frontend and backend systems, REST APIs and MongoDB database. Key components included encrypted storage, permission controls, activity tracking, personal and shared vaults, Web3 wallet connections, smart contract integration, security notifications, global search and responsive design.

Client Background

Andrew King works in the cybersecurity and credential management industry. He identified that passwords, access keys and confidential information were often managed across different tools, making secure access and sharing difficult. He needed a single platform that could support passwordless login, temporary and permanent sharing, permission controls, instant access removal and Web3 identity features.

Project Overview

Project Scope

Our work included:

  • Requirement analysis and workflow planning
  • UI/UX design
  • Frontend, backend and API development
  • MongoDB and Mongoose setup
  • Passwordless login and session management
  • Secure vaults for credentials and notes
  • Secret sharing and access control
  • Team workspace features
  • Web3 and smart contract integration
  • Activity logs and security notifications
  • Search, filters and dashboard features
  • Functional and security testing
  • Performance improvements

Target Audience

LockYantra is designed for:

  • Individuals
  • Developers and DevOps teams
  • IT and security teams
  • Startups and SaaS companies
  • Digital agencies
  • Businesses handling client access
  • Organisations managing sensitive data
  • Web3 users and companies

Objectives

The main objectives were to:

  1. 01Replace traditional password-based login
  2. 02Protect sensitive credentials and reduce the risk of leaks
  3. 03Simplify secure sharing across teams
  4. 04Give users control over permissions, access duration and revocation
  5. 05Make security activity easier to track
  6. 06Support personal, team and Web3 use cases
  7. 07Build a scalable platform for future growth

Business Challenge

  1. 01Passwords, API keys, SSH keys, recovery codes and private documents were often stored across browsers, spreadsheets, emails and personal devices.
  2. 02This made sensitive information difficult to organise and increased the risk of accidental sharing or unauthorised access.
  3. 03Sharing credentials through email or messaging platforms also gave owners limited control after the information was shared.
  4. 04Teams needed to control who could view, edit or reshare each item. They also needed temporary access and quick access removal.
  5. 05Traditional password-based login created another password that users had to remember and protect.
  6. 06The main challenge was to combine secure login, safe storage, controlled sharing, team access and activity tracking in one platform.

Our Solution

We built LockYantra with a secure digital vault where users could store passwords, API keys, SSH keys, recovery codes and private documents in one place. Magic-link login removed the need for a traditional account password. Users could share selected information with team members or clients and control who could view, edit or reshare it. Access could be temporary or permanent and revoked whenever required. Team vaults and workspace roles made it easier to manage shared credentials. Activity logs recorded logins, access, sharing and permission changes. Real-time alerts also informed users about important security activity. Web3 wallet and smart contract support were added for blockchain-based identity features.

Key Features

LockYantra includes the following main features:

Key feature groups sized by number of capabilitiesMagic-link login with email verificationSecure session and device managementPasswordless AuthenticationEncrypted storage for credentials and confidential filesSeparate personal and team vaultsSecure VaultsSecure sharing with team members or clientsTemporary, permanent and one-time accessView, edit and share permissionsInstant access revocationSharing and Access ControlMember invitations with workspace rolesShared vault managementTeam WorkspaceFolders, collections and tagsGlobal search & filtersOrganisation and SearchLogin, access and sharing recordsPermission and device activityReal-time security and expiry alertsActivity and Security AlertsWallet connection and authenticationBlockchain identity verificationSmart contract supportWeb3 SupportVault, sharing and expiry overviewClear vault and access controlsResponsive design for desktop and mobileDashboard and User Experience
02Passwordless Authentication
01

Passwordless Authentication

  • Magic-link login with email verification
  • Secure session and device management

Development Process

We began by analysing the main requirements for secure storage, passwordless login, sharing, permissions, team access, activity tracking and Web3 support. Based on these needs, we planned the complete flow from login and vault access to sharing, revocation and security monitoring.

Technical Challenges

01

Passwordless account access

Magic-link login and email verification were added.

02

Protecting sensitive data

AES-256 encryption and secure storage were used.

03

Managing different secret types

A flexible structure supported passwords, keys, codes, notes and documents.

04

Managing shared access

View, edit and share permissions were added with expiry, one-time access and instant revocation.

05

Supporting personal and team vaults

Workspace roles and shared collections were created.

06

Tracking activity and alerts

Important actions were recorded and Socket.IO sent real-time notifications.

07

Adding Web3 identity support

Wallet connections and blockchain verification were integrated.

08

Handling large vaults

Search, filters, pagination and optimised queries were used.

09

Supporting mobile users

Vault and sharing screens were adapted for smaller devices.

Technology Stack

Frontend
Next.js logo

Next.js

Frontend
TypeScript logo

TypeScript

Frontend
Tailwind CSS logo

Tailwind CSS

Backend and APIs
Node.js logo

Node.js

Backend and APIs
Express.js logo

Express.js

Backend and APIs
REST APIs logo

REST APIs

Database
MongoDB logo

MongoDB

Database
Mongoose logo

Mongoose

Authentication
Magic-link authentication logo

Magic-link authentication

Authentication
JWT logo

JWT

Authentication
email verification logo

email verification

Real-Time Communication
Socket.IO logo

Socket.IO

Web3 and Blockchain
WalletConnect logo

WalletConnect

Web3 and Blockchain
MetaMask logo

MetaMask

Web3 and Blockchain
Ethers.js logo

Ethers.js

Web3 and Blockchain
smart contracts logo

smart contracts

Storage
Encrypted MongoDB storage logo

Encrypted MongoDB storage

Storage
cloud object storage logo

cloud object storage

Deployment
Docker logo

Docker

Deployment
Nginx logo

Nginx

Deployment
GitHub Actions logo

GitHub Actions

Design Decisions

The interface was designed to keep security controls clear and easy to use. Important decisions included:

  • Simple magic-link login
  • Separate personal and team vaults
  • Hidden values with quick-copy actions
  • Categories, search and filters
  • Separate panels for sharing and permissions
  • Role, access and revocation controls
  • Expiry and limited-view settings
  • Activity, alerts and security summaries
  • Clear wallet connection status
  • Responsive vault screens

SEO Work

SEO work focused on public pages while keeping private pages hidden from search engines. Main work included:

  • Page titles, descriptions and headings
  • Clean URLs, keywords and internal links
  • Image optimisation and alt text
  • Sitemap, robots.txt and canonical tags
  • Social sharing tags
  • Public-page indexing
  • No-index settings for login and vault pages

Performance Optimization

Performance work included:

  • Next.js component optimisation
  • Lazy loading
  • Reduced unnecessary API calls
  • MongoDB query optimisation
  • Database indexing
  • Pagination for larger vault records
  • Fast global search
  • Optimised Socket.IO events
  • Controlled attachment loading

Security

Protecting passwords, keys and private data was a key part of the platform. Security measures included:

  • Passwordless login
  • Email verification and JWT
  • Secure sessions and device control
  • AES-256 encrypted storage
  • HTTPS and protected APIs
  • Role-based permissions
  • Instant access revocation
  • CSRF and rate-limit protection
  • Input validation
  • Secure file access
  • Activity logs

Architecture Diagram

Credential Management Improvements

  1. 01

    Credentials could be stored across different tools.

    Passwords, keys and documents can be stored inside an encrypted vault.

  2. 02

    Users depended on traditional account passwords.

    Magic links provide passwordless account access.

  3. 03

    Sensitive information could be shared through email or chat.

    Secrets can be shared through controlled links and permissions.

  4. 04

    Shared access could remain active after it was no longer needed.

    Expiry dates, one-time access and instant revocation are available.

  5. 05

    Different access levels were difficult to manage.

    View, edit and share permissions can be controlled separately.

  6. 06

    Credential activity was difficult to track.

    Audit logs record access, sharing and permission changes.

  7. 07

    Personal and team records could become mixed.

    Personal vaults and team workspaces keep information organised.

  8. 08

    Important security actions could be missed.

    Real-time notifications show login and sharing activity.

  9. 09

    Wallet identity was handled separately.

    Web3 wallet and blockchain identity features are supported.

Results

For Individuals

  1. 01Users can manage passwords, recovery codes, licences, private notes and confidential documents through a secure vault.

For Web3 Users

  1. 01Users can connect supported wallets and use blockchain-based identity features.

Business Impact

LockYantra gave the client one secure platform for managing personal and team credentials. It reduced dependence on scattered tools and made sharing, permissions and access removal easier to control. The platform also gave the client a stronger base for serving individuals, teams and businesses while adding new security features and services in the future.

Business Impact
1,250+Monthly Active Users
Business Impact
820+Active Personal and Team Vaults
Business Impact
18,500+Secrets Stored
Business Impact
4,200+Credentials Shared
Business Impact
1,600+Temporary Access Created
Business Impact
780+Access Revocations
Business Impact
97.8%Magic-Link Success Rate
Business Impact
1.8 secondsAverage Page-Load Time
Business Impact
240 msAverage API Response Time

Visual Identity

Visual Identity

LLockYantra

Aa

LockYantra

Color

  1. #5046E3
    01Primary Purple80 70 227
  2. #0C8CB9
    02Cyan Blue12 140 185
  3. #020617
    03Dark Navy2 6 23
  4. #121B2C
    04Panel Background18 27 44
  5. #1F2938
    05Secondary Panel31 41 56
  6. #FFFFFF
    06Primary Text255 255 255
  7. #8790A0
    07Secondary Text135 144 160
  8. #2D3758
    08Border Gray45 55 88
  9. #5DDBAE
    09Success Green93 219 174
  10. #F5C940
    10Warning Yellow245 201 64
  11. #E993A8
    11Alert Pink233 147 168

Type

  1. 01 · Primary4 weights

    Archivo

    ABCDEFGHIJKLMNOPQRSTUVWXYZ
    abcdefghijklmnopqrstuvwxyz
    0123456789

    • Bold
    • Semibold
    • Medium
    • Regular

Client Testimonial

We chose Team TISA to build LockYantra because we needed a platform that could manage sensitive credentials more securely. The team understood our requirements, listened to our feedback and made changes whenever needed. LockYantra has made sharing credentials and managing access much simpler for us. We are satisfied with the result and thankful to the team for their work.
A
Andrew King (AK)

Future Scalability

In the future, LockYantra can include:

  1. 01

    Passkey and biometric login

  2. 02

    Single sign-on for businesses

  3. 03

    Automated credential rotation

  4. 04

    Approval workflows and emergency access

  5. 05

    Advanced audit reports

  6. 06

    Browser extensions and mobile apps

  7. 07

    Cloud and developer integrations

  8. 08

    Support for more blockchain networks

Lessons Learned

The LockYantra project helped us understand that:

  1. 01

    Passwordless login should stay simple and secure

  2. 02

    Access rules should cover permissions, expiry and revocation

  3. 03

    Logs and alerts must not reveal sensitive information

  4. 04

    Personal and team vaults need clear ownership

  5. 05

    Web3 and mobile features should be easy to use

  6. 06

    Future needs should be planned early

Conclusion

LockYantra brings passwordless access, secure credential storage and controlled sharing into one organised platform. It helps individuals and teams handle sensitive information without making everyday use complicated. The project gave the client a product that supports both personal and professional credential management needs.