The secure home for your team's secrets.
Environment variables and credential files in one encrypted vault. Control who sees what, roll back recent changes, and pull them into any environment with one command.
Free plan · No credit card required
Environment variables production
- Encrypted at rest
- Post-quantum transport
- Passkeys & 2FA
- Versioned with rollback
- Activity log
From scattered .env files to one source of truth.
Set it up once for your team. Every developer and every pipeline gets exactly the secrets it needs.
Organize
Group secrets by organization, app and environment — the way you already deploy.
Store
Add variables and credential files like .pem, .p12 or a Firebase service account.
Use
Install the CLI from npm and pull them onto your machine or into your CI. No more copy-paste.
Everything a team needs to keep secrets under control.
Designed around how teams actually ship: many apps, many environments, and people who should only see what they need.
Every change versioned
See who changed what and when, compare versions and roll back in one click.
Credential files
Keep certificates and keys next to your variables.
Access by environment
Owners, admins and members, down to each environment.
Activity log
A record of the changes made in your organization.
Scoped API keys
Give each pipeline read access to only the environments it needs.
Sign in to the CLI safely
Approve each device from the browser with a one-time code, and revoke it anytime.
Built for your pipelines
Pull secrets in GitHub Actions or any CI with a scoped API key.
How your secrets are protected.
No buzzwords — this is exactly what happens to a secret, from your terminal to our storage.
- Encrypted at restA key derived per record, bound to its context so values can't be swapped between records.
- Post-quantum transportRequests that carry secrets travel in a post-quantum encrypted channel on top of HTTPS.
- Device-bound CLIOnce you sign in, the CLI signs every request with its device key, so a copied token can't be used from another machine.
- Two-factor and passkeysProtect accounts with an authenticator app or passkeys, and approve CLI devices one by one.
What happens when you run smart-grow cloud_download
Need it on your own infrastructure? Self-hosted edition →
Start free. Upgrade when your team grows.
Every plan includes encryption, versioning, the CLI and the activity log.
- 1 organization
- 3 apps per organization
- 2 environments per app
- 50 variables per environment
- 2 secure files per environment
- 2 API keys
Paid plans from $4.99/month with more apps, environments and members.
Questions, answered.
Something else? Write to [email protected].
Who can see my secrets?
Only the members you give access to, per environment, and the API keys you create. Secret values are masked in the dashboard, but anyone who can read an environment can download its values with the CLI. Smart Vault is not end-to-end encrypted: our service decrypts values to answer authorized requests.
Does it work in CI/CD?
Yes. Create an API key limited to the environments your pipeline needs, and the CLI's cloud_sync command downloads your variables in any runner.
Can I export my data?
Yes. Download the variables you have access to as a JSON or .env file, and download your secure files, whenever you want.
Is there a self-hosted edition?
Yes. It runs on your own infrastructure: your secrets, database and encryption keys stay with you, and the CLI and API keys work against your own URL. The only connection to us is a periodic license check that sends no secrets. Contact us to get access.