Security leads
Need a lightweight inventory before rolling out formal endpoint, IAM, or access-review processes.
Product brief
PubKeySpace helps small teams see local key material, signing posture, passkey review surfaces, MCP configs, and stale credential risk without turning the product into a new secret store.
Who it is for
Need a lightweight inventory before rolling out formal endpoint, IAM, or access-review processes.
Need visibility into SSH keys, Git signing, MCP config, and team auth posture without blocking developers.
Need practical security hygiene before SOC 2, enterprise pilots, or customer security reviews force the issue.
Private alpha
Scanner and dashboard for SSH keys, Git signing posture, GPG key inventory, MCP clients, passkey review surfaces, stale credentials, and risky auth surfaces.
Signed export bundles, organization tokens, enrollment profiles, collector daemon, collector health, and browser team dashboard.
Configurable policy for approved MCP servers, passkey surfaces, annotations, suppressions, owners, tags, and expirations.
Manual setup help for design partners so the first product decisions are shaped by real team workflows.
Trust boundary
No private key contents.
No token values.
No MCP environment secret values.
No cloud upload unless a team explicitly enables collection.
Access
Send your team size, developer environment, and what currently worries you most about key or credential sprawl.