Skip to content

product / secrets

Secrets management

Keep keys and passwords out of files and chats: stored encrypted, handed to the command that needs them, with a record of who read what.

One vault, split by project and environment

Variables and files are encrypted at rest and belong to one project and one environment. Each person also has a personal space, and the organization has a shared one.

What is included
  • Variables and files: .p8, .p12, keystores, service-account JSON
  • Every change is a new version you can go back to
  • Values are never listed: only names, versions and dates
Vault
DATABASE_URL

productionstagingv7read 2 minutes ago

STRIPE_SECRET_KEY

productionv3read 1 hour ago

SMTP_PASSWORD

productionstagingv2read yesterday

apns_key.p8file

productionv1read 28 Sep

Two people for a change, a record for every read

A change to a protected secret waits for a second person: whoever asked cannot approve it, and a machine never decides. Every read is written down.

What is included
  • Four-eyes approval on changes
  • Audit of every read: who, what, when
  • Per-person overrides without touching the shared value
Approvals and audit

Change requested on STRIPE_SECRET_KEY

luca · production

Waiting for approval

ci-deploy read DATABASE_URL2 minutes ago

marta read STRIPE_SECRET_KEY1 hour ago

automator-01 read SMTP_PASSWORDyesterday

Secrets reach the command, never the disk

Start your app through the CLI and it receives its secrets as environment variables. There is no .env file to leak, copy or forget.

What is included
  • cyi run injects secrets into any command
  • Push sync to GitHub Environments
  • Service accounts for CI, limited to the environments you choose
Terminal

$ cyi run -p drogheria -e production -- bin/rails server

→ 14 secrets injected as environment variables

→ nothing written to disk

$ ls .env

ls: .env: No such file or directory

The other areas