> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turen.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Secure storage

> How TurenOS protects provider and integration credentials

TurenOS stores provider keys, OAuth tokens, MCP credentials, and other declared secrets in its Secret Vault.

## Platform protection

| Platform | Protection                                                                    |
| -------- | ----------------------------------------------------------------------------- |
| macOS    | Login Keychain and Electron Safe Storage                                      |
| Windows  | DPAPI-backed protected storage                                                |
| Linux    | Secret Service through GNOME Keyring, KWallet, or another compatible provider |

Vault records are sealed with an OS-protected key. The database stores encrypted material and a key-ownership claim, not the plaintext key.

## Fail-closed behavior

TurenOS does not silently downgrade to plaintext credentials. Startup or credential operations fail when native secure storage is unavailable, locked, or belongs to another OS-protected key.

## Backups and migration

Copying a database to another machine does not automatically move its protected key. Export and reconnect providers through supported flows rather than copying encrypted records alone.

Before resetting a vault, back up any session data you need. Removing the database or Safe Storage key can make old credentials permanently unreadable.

## What the vault does not protect

Secrets deliberately placed in environment variables, shell history, source files, issue text, logs, or plain configuration remain outside the vault boundary.
