Skip to content

Advanced › Security

Security

How your secrets are protected, and what you can do to keep them safe.

How Smart Vault protects them

Values are encrypted before they are stored, with a key for each organization. Requests that carry them travel through a post-quantum encrypted channel on top of HTTPS, and after you sign in, the CLI signs every request with its device key. API keys used in CI are not tied to a device, so keep them in your CI's secret store. The Security Policy has the details, including what Smart Vault does not do.

Recommendations

  • Turn on two-factor authentication or add a passkey.
  • Give members only the environments they need, and remove people who leave the team.
  • Create one API key per pipeline, with read access only, and delete the ones you no longer use.
  • Add smart-grow.env to your .gitignore, and never commit it.