Release

1.6.7

Pick where your vault's replica lives — same continent, the far hemisphere, or none — right at checkout, and watch the route on the network map.

Clavitor 1.6.7

Vault, CLI, proxy, and the clavitor.ai gate now ship on one version line — 1.6.7 across all four. The headline change is a new resilience option, not a version-numbering exercise.

Geographic vault replicas (new)

You can now choose a replica location for your vault at checkout:

  • Cross-hemisphere — your replica sits on the far side of the planet from your primary.
  • Same continent — your replica stays close, for lower-latency reads if your primary ever needs to fail over regionally. This is now the default.
  • None — no replica, if you'd rather opt out.

Clavitor picks the specific paired city for you (for example, a Zürich vault pairs cross-hemisphere with Dallas). The replica only ever receives ciphertext over an authenticated channel — it cannot read your vault, only hold a sealed copy of it. You can see the pairing live on the network page.

Vault

  • Vault 1.6.7 is now running fleet-wide across our 24 points of presence, rolled out canary-first.

Gate (clavitor.ai)

  • Fixed hardware-key login (YubiKey / passkey): a subset of logins were completing the security-key ceremony but failing to open a session, or landing on a blank vault page afterward. Both are resolved.
  • SCIM user provisioning for Enterprise/MSP customers on Okta is now available.

CLI

  • Fixed a crash: clavitor-cli --help | head (or any command whose output hits a closed pipe) used to abort; it now exits cleanly, matching normal Unix tool behavior.

Proxy

  • Rebuilt at 1.6.7 on the same shared client and crypto core as the CLI and vault. No behavior changes in this release — the version number now simply tracks the rest of the fleet.

---

Breaking changes: None.

Known issues: None reported.