Coverkey

Built to hold your keys.

Coverkey holds the logins your business can't afford to lose — so how it's protected isn't a footnote, it's the product. Here is exactly what we do, in plain words. Everything on this page is true of the system as it runs today.

Locked by default, unlocked on purpose

A login can only be opened while its owner is marked On cover or Left the business. That rule is enforced inside the database itself — not just by the screens — so there is no quiet path around it. Switch someone back to Active and their logins lock again, immediately.

Encrypted where they live

Usernames, passwords and authenticator setup keys are stored encrypted, with keys held separately from the data, in an EU data centre (Paris). They are never written into ordinary database columns, never sent to your browser until the moment an authorised admin deliberately opens a login, and never stored in the browser afterwards.

The authenticator key never leaves the database

The setup key behind a rotating 6-digit code is the crown jewel — anyone holding it can mint codes forever. So Coverkey computes the current code inside the database and hands out only the code itself, which expires within 30 seconds. The key stays put. Even our own servers only ever see the 6 digits.

Every view goes on a record no one can edit

Opening a login writes who, what and when to the activity log in the same instant. There is no edit and no delete for that record — for anyone, including the account owner. The database refuses the operation at the privilege level; it isn't a button we simply chose not to build.

Each business is walled off

Your data is separated from every other business with row-level security — rules the database applies to every single query, checked against the signed-in admin. One business can never see, edit or delete another's people, systems, logins or activity. We test exactly that before every release.

A person types the code. Always.

Nothing in Coverkey signs in to your systems, fills in forms, or automates access — we verified this claim against our own code line by line. Whoever's covering reads the code and types it in themselves, which keeps a person accountable for every access and keeps you inside each service's rules.

Deleting really deletes

Remove a login and the stored username, password and setup key are destroyed on the spot — not flagged, not binned, destroyed. What remains is the activity log's record that views happened, because the record is permanent even when the login isn't.

Sign-in security for your admins

Admin passwords are hashed, never stored, and sign-in attempts are rate-limited to blunt guessing. Every page verifies the session freshly on each request, a removed admin is cut off on their very next click, and a password reset never signs anyone in automatically.

And the honest part: no one can promise a system is unhackable, and anyone who does should worry you. What we can promise is layers — encryption, locked-by-default access, isolation between businesses, a record no one can quietly tidy — so that no single failure hands anything over, plus a security review before every release.

Seen something that doesn't look right, or want to ask how something works before trusting us with your logins? Write to support@coverkey.co.uk — security questions go to the front of the queue.