Skip to content

The secure home for your team's secrets.

Environment variables and credential files in one encrypted vault. Control who sees what, roll back recent changes, and pull them into any environment with one command.

Free plan · No credit card required

Smart Grow Vault App — Featured on Product Hunt
  • Encrypted at rest
  • Post-quantum transport
  • Passkeys & 2FA
  • Versioned with rollback
  • Activity log
How it works

From scattered .env files to one source of truth.

Set it up once for your team. Every developer and every pipeline gets exactly the secrets it needs.

01

Organize

Group secrets by organization, app and environment — the way you already deploy.

02

Store

Add variables and credential files like .pem, .p12 or a Firebase service account.

03

Use

Install the CLI from npm and pull them onto your machine or into your CI. No more copy-paste.

Features

Everything a team needs to keep secrets under control.

Designed around how teams actually ship: many apps, many environments, and people who should only see what they need.

Every change versioned

See who changed what and when, compare versions and roll back in one click.

Credential files

Keep certificates and keys next to your variables.

Access by environment

Owners, admins and members, down to each environment.

Activity log

A record of the changes made in your organization.

Scoped API keys

Give each pipeline read access to only the environments it needs.

Sign in to the CLI safely

Approve each device from the browser with a one-time code, and revoke it anytime.

Built for your pipelines

Pull secrets in GitHub Actions or any CI with a scoped API key.

Security

How your secrets are protected.

No buzzwords — this is exactly what happens to a secret, from your terminal to our storage.

  • Encrypted at restA key derived per record, bound to its context so values can't be swapped between records.
  • Post-quantum transportRequests that carry secrets travel in a post-quantum encrypted channel on top of HTTPS.
  • Device-bound CLIOnce you sign in, the CLI signs every request with its device key, so a copied token can't be used from another machine.
  • Two-factor and passkeysProtect accounts with an authenticator app or passkeys, and approve CLI devices one by one.

What happens when you run smart-grow cloud_download

Need it on your own infrastructure? Self-hosted edition →

Pricing

Start free. Upgrade when your team grows.

Every plan includes encryption, versioning, the CLI and the activity log.

Free
$0 / month

For personal projects and small teams getting started.

  • 1 organization
  • 3 apps per organization
  • 2 environments per app
  • 50 variables per environment
  • 2 secure files per environment
  • 2 API keys

Paid plans from $4.99/month with more apps, environments and members.

FAQ

Questions, answered.

Something else? Write to [email protected].

Who can see my secrets?

Only the members you give access to, per environment, and the API keys you create. Secret values are masked in the dashboard, but anyone who can read an environment can download its values with the CLI. Smart Vault is not end-to-end encrypted: our service decrypts values to answer authorized requests.

Does it work in CI/CD?

Yes. Create an API key limited to the environments your pipeline needs, and the CLI's cloud_sync command downloads your variables in any runner.

Can I export my data?

Yes. Download the variables you have access to as a JSON or .env file, and download your secure files, whenever you want.

Is there a self-hosted edition?

Yes. It runs on your own infrastructure: your secrets, database and encryption keys stay with you, and the CLI and API keys work against your own URL. The only connection to us is a periodic license check that sends no secrets. Contact us to get access.

Stop sharing secrets over chat.

Set up your team's vault in minutes.