Skip to content
FAQ

Frequently asked questions

Answers about Smart Vault, security, billing and the CLI. Something else? Write to [email protected].

General

What is Smart Vault?

Smart Vault is a platform to manage environment variables and credential files for your applications. You organize them by organization, app and environment, control who can see and change each environment, keep a version history, and pull them into any machine or pipeline with the CLI.

How do I get support?

Email [email protected]. We answer in order of arrival on business days, with security issues and outages first. We do not currently guarantee response times.

Where can I find the documentation?

In the docs: getting started, the CLI, API keys and CI/CD.

Security

How is my data protected?

Your variables and files are encrypted before they are stored, with a key unique to your organization and a separate key derived for each record. Requests that carry them travel inside an additional post-quantum encrypted channel, on top of HTTPS. The Security Policy has the details.

Who can see my secrets?

The members of your organization, according to their roles and the permissions of each environment, plus the API keys you create. Our service decrypts values only to answer requests you or your team authorize. Smart Vault is not end-to-end or zero-knowledge encrypted, which means our infrastructure holds the keys needed to decrypt. Our staff do not access your secrets unless you ask for support that requires it or the law requires it.

What happens if I lose my password?

Reset it from the sign-in page. Your stored variables and files are not encrypted with your password, so resetting it does not affect them.

Do you support two-factor authentication?

Yes. Accounts with a password can turn on two-factor authentication with an authenticator app, which also gives backup codes. Every account can add passkeys. We recommend one of them for every account.

Do you have SOC 2 or ISO 27001? Are you GDPR compliant?

We have not completed any audit or certification yet. Our Privacy Policy explains what data we collect, why, and how to exercise your rights, including access, correction, deletion and export.

Pricing

What plans do you offer?

Five: Free, Personal, Pro, Business and Enterprise. Each one has limits for organizations, apps, environments, variables, members, files and API usage. See Pricing.

Can I change my plan?

Yes, from Billing settings. Plan changes and any proration are handled by our payment provider, Polar.

What is your cancellation policy?

Cancel any time from Billing settings. Your paid features stay active until the end of the billing period, and then your account moves to the Free plan. We do not refund unused time, except where the law requires it.

How can I pay?

Payments are processed by Polar, which accepts major credit and debit cards.

Is there a free trial?

The Free plan has no time limit, so you can use Smart Vault before paying for anything.

Technical

Which languages and frameworks does it work with?

Any. The CLI writes your variables to a dotenv file, which every stack can read.

Can I use it in CI/CD?

Yes. Create an API key limited to the apps and environments the pipeline needs, and run the CLI's cloud_sync command (and cloud_sync_file for secure files) in GitHub Actions, GitLab CI or any other runner. Keys expire after 90 days by default. The docs show the steps.

Do you keep a history of my variables?

Yes. Every change creates a version. We keep the three most recent previous versions of each variable, and you can compare them and roll back from the dashboard.

What files can I upload as secure files?

Certificates and keys (.pem, .crt, .cert, .key, .p8, .p12, .pfx), keystores (.jks, .keystore), Apple provisioning profiles (.mobileprovision, .provisionprofile) and configuration files (.json, .env, .yaml, .yml, .toml, .xml, .properties, .cfg, .conf, .ini). They are encrypted like your variables.

Are there API limits?

Yes. Each plan has a monthly request quota and a per-minute limit for API keys. See Pricing.

Can I export my data?

Yes. Download the variables you have access to in any environment as a JSON or .env file from the dashboard, and download secure files from the dashboard or with the CLI. Exports include only what your role and plan give you access to.

CLI

How do I install the CLI?

npm i -g @smart-dev-agency/smart-grow-secure-cli. The command is smart-grow.

Can I use it for local development?

Yes. smart-grow cloud_login signs you in with a device code that you approve in the browser. Then smart-grow cloud_download asks for the organization, app and environment and writes the variables to a dotenv file (smart-grow.env by default), and smart-grow cloud_download_file downloads your secure files.

Can my team work on the same variables?

Yes. Invite members to your organization and give each one a role and per-environment permissions. Individual changes to variables, and changes to files, apps, environments and member permissions, are recorded in the activity log.

Can I move my variables from another tool?

Yes. Paste or drop a JSON object into any environment to import its keys in bulk. There are no automatic importers for other services.