Secrets Vault
AES-256-GCM encrypted environment variables — injected at deploy time, never in Git.
Select a project above to manage its secrets.
Encrypted at rest
AES-256-GCM. The plaintext value never touches the database, logs, or audit trail.
Injected at deploy
Decrypted in-memory during the deploy saga and fed directly to the platform adapter.
Rotation alerts
Flag any key for rotation without deleting it. The value stays until you re-enter it.