Security
Vault
Keep API keys, tokens and private keys out of spreadsheets and chat. Vault stores them encrypted and lets only admins read them back.
In the dashboardKey Vault & Secrets
Store a secret
- Choose Create
Give it a name your team will recognise, like
stripe_secret_key, and pick the environment it belongs to: production, staging or development. - Paste the value
It is encrypted with AES-256-GCM before it is stored. The value is shown once while you create it; closing the dialog clears it from the page.
Read a secret back
Choose Reveal on the secret. Only owners and admins can reveal values; viewers can see that a secret exists but never its contents.
Encryption keys
| Key | What it is |
|---|---|
| TrustPort-managed key | Encrypts your stored secrets with AES-256-GCM. TrustPort manages and rotates it. |
| Your own keys (BYOK records) | A register of the AWS KMS, Google Cloud KMS, Azure Key Vault or HashiCorp Vault keys your workspace uses, with provider and key ID. |
Registering your own key records it for your inventory. TrustPort doesn't call your key management service and doesn't use that key to encrypt Vault secrets.
Remove a secret
Delete secrets you no longer use. Deleting can't be undone, so rotate the secret at its source first.