The credentials you need most are the ones you cannot reach.
Your password manager is behind the SSO that is down. The one admin with the root account is on a plane. Break Glass Business keeps emergency credentials, contacts and recovery procedures in a vault that survives your other systems — and that no single person can open alone.
Two responder seats free forever · unlimited recipients on every plan · no card to start
The failure this prevents
Key-person risk
One person holds the root credentials, the domain registrar login, and the knowledge of how the failover actually works. They leave, or they are simply asleep. Everyone else waits.
Circular dependency
The recovery plan lives in the wiki that authenticates through the identity provider that is currently down. The plan is perfect and completely unreachable.
No trail afterwards
Someone got in and fixed it. Nobody can say who, with what, or on whose authority — which is the question the auditor, the insurer and the board all ask next.
How it works
Store what a crisis needs
Break-glass accounts, recovery codes, registrar logins, out-of-band contacts, and the runbook for using them. Encrypted in your browser before it leaves the device.
Split the keys across your people
Each secret is sealed under a K-of-N quorum. Two of five, three of seven — you choose. No one person can open it, and that includes us.
Rehearse it before you need it
Scheduled drills fire the real call tree and run the real playbook against a practice incident. The record they leave is the evidence your auditor wants.
No single person can open a secret
Every team secret is encrypted with a key that is mathematically split into shares — one per key holder. Opening it needs a quorum of them to agree, in the moment, with a stated reason.
Requesting is a deliberate act
A holder opens a request and says why. Every other holder sees that reason before they decide. Approving decrypts their share in their own browser and re-encrypts it to the requester — the server never sees a share in the clear.
Our staff cannot read your vault
Not as policy — as arithmetic. We hold ciphertext and a set of shares encrypted to your people’s public keys. A complete database dump yields nothing without a quorum of your team’s passwords. There is no support override, because there is nothing to override.
Reaching people when the usual channels are gone
Escalation that actually escalates
Push and email immediately. SMS at ten minutes. A phone call at thirty. Each step chases only the people who have not acknowledged, and stops for each person the moment they do.
Recipients are free, on every plan
You pay for responders — the people who sign in, hold keys and approve access. Notifying four thousand staff costs nothing extra, because charging per head to warn people is a bad way to make money.
Evidence, generated rather than written
Most companies answer “show me your break-glass procedure and prove you have tested it” with a document written the week before the audit. Break Glass produces the real answer as a side-effect of being used: the drills that ran, the requests that were approved and by whom, the contacts that were verified.
Export it as a single self-contained file, mapped to the controls your framework actually names — ISO 27001 A.5.29 and A.8.2, SOC 2 CC6.1 and A1.2, DORA Articles 11 and 17, NIS2 Article 21. See how the mapping works.
Set it up before you need it
Two responder seats free forever. Enough to define a real break-glass procedure and test it end to end.
Start free