AI-first project workspace

Everything your projects run on, in one workspace.

Repositories, domains, servers, tech stack, deployments and documents — with credentials and .env vars stored right where they belong. Organized per project, shared with your team, access-controlled.

One home per projectRole-based accessSecrets masked by defaultFull activity log
acme-webWeb app
StackNext.jsPostgresVercel
Repositorygithub.com/acme/web
Domainacme.com Live
Serverprod-1 · sgp1
Credentials & env8 secrets
STRIPE_SECRET_KEY
DATABASE_URLpostgres://…5432/acme Revealed
DATABASE_URLrevealed by you · just now · logged

Built for the teams who hold the keys

FoundersIndie hackersSmall software teamsAgenciesFreelancers
Why it exists

The scattered way of working, replaced

Most small teams keep their operational knowledge in a dozen places. Kyron pulls it into one.

Repo in one place, domain in another, deploy notes in someone’s head.

Now

One project page with its stack, repos, domains, servers and docs together.

Secrets and env vars scattered across .env files, spreadsheets and DMs.

Now

Credentials stored with their project — masked by default, audited on reveal.

No clear picture of who on the team can touch what.

Now

Role-based access per project and a full activity log across the workspace.

Everything in one place

Built around your projects

Nine connected modules, all hanging off the project they belong to — so the repo, the domain, the database, the server and the secret are one click apart, not one search away.

Projects hub

Every project gets one page — its tech stack, repositories, domains, servers, docs and secrets. Open a project and see everything it runs on.

Repositories

Connect the git repositories behind each project, so the code — and exactly where it lives — is never a guess or a Slack search.

Servers & domains

Keep hosts, IPs and domains beside the projects that run on them. No more hunting through email for that one DNS record.

Databases

Which provider holds a project’s database, which environment it serves, and which stored credential is its login — without the connection string ever leaving the vault.

Deployments

Track what is live where, per environment — type-aware for web, mobile and services, so the record fits the project.

Documents

Runbooks, onboarding notes and architecture decisions in markdown, versioned alongside the work instead of lost in a drive.

Assets

Logos, brand files and design exports in project folders, so the thing everyone asks for on Slack has an address.

Analytics

What the workspace holds and how much of your plan it uses — projects, members and storage, counted rather than guessed.

Credentials & env

API keys, passwords, tokens and environment variables — stored with the project they belong to, masked by default and reveal-audited.

How it works

Set up in three steps

From empty workspace to your whole team working from one source of truth.

01

Create your workspace

Spin up a workspace for your company in seconds. No credit card, no setup call.

02

Add your projects

Bring in each project with its repos, domains, servers, stack, docs and secrets.

03

Invite your team

Add teammates with scoped roles so everyone gets exactly the access they need.

Team & roles

Your team, with exactly the right access

A workspace is only useful if the whole team lives in it. Invite everyone, then let roles decide who can see, edit or reveal each project and its secrets — so access maps to responsibility, and nothing leaks by accident.

Scoped roles

Owner, admin, member or a role you define. Each role is a clear boundary, not a vague setting.

Per-resource access

Decide who can view, edit or reveal each project, credential and document — down to the resource.

Invite in seconds

Add teammates by email and they are productive in minutes. Contractors get scoped access that expires when the work does.

Attributed activity

Every change is tied to a person, so the workspace can always tell you who did what, and when.

Members4 people
K

You(you)

Full access

Owner
AR

Aditi R.

Manage projects

Admin
MK

Marcus K.

View & deploy

Member
JD

Jamie D.

Docs only

Contractor
Contractor can see documents, but never reveal a secret.
Integrations

Connect the services your projects already run on

Give the workspace a read-only token and it can talk to your provider directly — starting with GitHub. Available on Pro and above.

GitHub

acme-inc

Connected
Access token
encrypted

Not shown again — not even to you.

Read repositoriesGranted
Read organisationGranted
Write anythingNever requested
  • Verified before it is saved

    The token is checked against the provider the moment you paste it. A wrong or expired one fails there and then, instead of sitting in your workspace looking connected.

  • The token never comes back out

    It is encrypted, used only by our servers, and there is no screen anywhere that will show it to you again — deliberately, unlike the credentials vault, because nobody needs to read it.

  • Read-only, by design

    We only ever read from your provider. Nothing in the product can create, rename or delete anything on your GitHub — so a bug on our side cannot touch your repositories.

GitHub connects today. Pulling repositories in automatically is the next release, and more providers follow it.

Security by default

Secrets stay the most protected part

Credentials and env vars live alongside the rest of a project, but they’re held to a higher bar — masked, audited and access-controlled, so keeping everything together never means keeping it exposed.

Two-factor, and again to reveal

Turn on an authenticator and every sign-in asks for a code — no trusted-device exemption. Revealing a stored secret asks again, and a code only works once.

Masked by default

Secrets live in the same workspace as everything else — and they are its most protected part. Hidden until someone deliberately reveals them.

Reveal audit trail

Every time a value is unmasked it is recorded — who, what and when — so exposure is never silent.

Role-based access

Granular roles decide who can view, edit or reveal. Access maps to responsibility.

Full activity log

A running history of changes across projects, credentials and team, so nothing happens off the record.

Also from Kyron Infotech

KyAuth, the authenticator we built for this

Kyron Deck asks for a six-digit code at sign-in. Any authenticator can give you one — Google Authenticator, 1Password, Bitwarden. We built KyAuth because we wanted a better one.

  • Fully offline

    Zero network calls. Not telemetry, not fonts, not update checks — so opening it reveals nothing about which services you use.

  • Secrets encrypted at rest

    Held in an encrypted database behind a hardware-backed key, unlocked with your fingerprint or device PIN.

  • Standards only

    RFC 6238 and the standard QR format, so it works with everything — and you can move to another app whenever you like.

Coming to Android and iOS. Kyron Deck works with any authenticator app in the meantime.

Pricing

Free while we build.

Every plan is open during early access — pick the one you will grow into and pay nothing for it yet.

Free

$0

For founders and small teams getting organized.

  • 3 projects
  • 5 members
  • 1 GB storage
  • The full workspace — projects, repos, domains, servers, databases, deployments, docs and assets
  • Credentials & env vars, masked by default and audited on reveal
  • Two-factor authentication
  • Role-based access and activity log
Start free

Pro

Most complete

$29/month

Not billed during early access

For teams running more than they can hold in their heads.

  • 50 projects
  • 25 members
  • 20 GB storage
  • Everything in Free, with room to grow
  • Integrations — connect GitHub with a read-only token
  • Higher caps on projects, members and storage
Start free

Enterprise

$99/month

Not billed during early access

For companies that have to be able to prove what happened.

  • Unlimited projects
  • Unlimited members
  • 100 GB storage
  • Everything in Pro
  • Immutable audit log, exportable to CSV
  • No cap on projects or members
Start free

Kyron Deck is in early access, so nothing is billed yet — pick any plan and use it free while we build. Prices are what they will be when billing opens, and we will tell you before that happens.

FAQ

Questions, answered

Everything it runs on: its tech stack, git repositories, servers, domains, deployments and markdown documents — plus its credentials and environment variables. Open one project and you have the full picture in one place.

Get started

Bring your projects together.

Create your workspace in seconds and give your team one place for every repo, domain, document and secret. Free to start, no card required.