[Developers]

Secrets Management

service credentials stored in configuration files, passwords shared over email, certificates that expire without warning: these are the credential hygiene failures that show up in post-incident reviews. The Secrets Manag

Category: ManagementLast Updated: Feb 5, 2026
managementreal-timecomplianceblockchain

Overview#

service credentials stored in configuration files, passwords shared over email, certificates that expire without warning: these are the credential hygiene failures that show up in post-incident reviews. The Secrets Management module centralises every credential used by the platform in an encrypted vault with automated rotation, expiration tracking, and a complete audit trail for every access event.

For multi-tenant deployments, each organisation's credentials are cryptographically isolated from every other tenant's, with independent access controls and separate audit trails.

Key Features#

  • Multi-Tenant Secret Vault: Cryptographically isolated secret storage per tenant with independent access controls and audit trails. Centralised management provides visibility across tenants while maintaining strict isolation boundaries that prevent cross-organisation credential access.

  • Comprehensive Secret Types: Purpose-built handling for service credentials, service passwords, OAuth tokens, SSL/TLS certificates, and complete OAuth credential sets. Each type includes format validation, appropriate security defaults, and lifecycle management specific to that credential format.

  • Secret Lifecycle Management: Manage secrets from creation through rotation to retirement. Credentials are encrypted at rest, tagged with metadata, assigned access policies, and configured with expiration dates. Soft deletion with configurable recovery periods prevents accidental data loss.

  • Automated Rotation: Schedule automatic rotation at configurable intervals (weekly, monthly, quarterly, or custom) with zero-downtime rotation, rollback capability, and notifications. On-demand manual rotation is available for immediate credential replacement when a compromise is suspected.

  • Expiration Management: Configurable expiration dates with progressive warnings at 30, 14, 7, and 1 day before expiry. Automatic deactivation on expiry with optional grace periods and emergency override capabilities prevent unexpected service interruptions from certificate or key expiry.

  • Fine-Grained Access Control: Role-based permissions for read, write, rotate, delete, and grant operations. Additional restrictions based on IP allowlists, time windows, service identity, and environment boundaries ensure credentials are accessible only to authorised consumers.

  • Usage Tracking and Monitoring: Track access patterns including retrieval counts, failed access attempts, last-accessed timestamps, and accessing services. Identify unused secrets and detect anomalous access patterns that may indicate a compromised credential.

  • Certificate Lifecycle: Track SSL/TLS, client, and CA certificate expiration with automated renewal support. Monitor certificate health across your deployment and receive alerts before certificates expire to avoid service disruptions.

  • Audit Trail: Every secret operation (creation, access, rotation, permission changes, deletion) is logged with full context and retained for compliance purposes. Real-time forwarding to SIEM systems is supported.

Use Cases#

  • Government departments centralising credentials for third-party API integrations, ensuring no secret lives in a configuration file on a developer laptop.
  • Intelligence organisations managing certificate lifecycles across distributed systems where an expired certificate could interrupt a critical data feed.
  • Financial institutions satisfying PCI DSS requirements for credential management, rotation, and access auditing without manual processes.
  • Healthcare providers rotating service account credentials on schedule to meet HIPAA technical safeguard requirements.
  • Critical infrastructure operators responding to a suspected compromise by immediately deactivating affected credentials and rotating all related secrets from a single interface.

Open Standards#

  • AES-256-GCM (NIST SP 800-38D / FIPS 197): All secret values are encrypted at rest using AES-256-GCM authenticated encryption, with per-row additional authenticated data (AAD) binding ciphertext to its tenant and record identity to prevent transplant attacks.
  • FIPS 140-2: The encryption layer targets FIPS 140-2 compliance, and optional Hardware Security Module (HSM) integration provides validated key storage for classified and regulated deployments.
  • PKCS#11: HSM-backed key wrapping is implemented via the PKCS#11 interface, allowing the master key encryption key (KEK) to reside in a hardware token rather than software memory.
  • SHA-256 (FIPS 180-4): A SHA-256 digest of every plaintext secret value is stored at rest and verified on each retrieval, providing cryptographic integrity assurance independent of the encrypted ciphertext.
  • JSON Web Token (RFC 7519) / OAuth 2.0 (RFC 6749): JWT secrets and OAuth tokens are first-class secret types with purpose-specific lifecycle management, and service-to-service calls to the secrets store are authorised using signed JWTs.
  • X.509 (ITU-T / RFC 5280): Certificates (SSL/TLS, client, and CA) are a dedicated secret type, with expiration tracking and automated renewal support aligned to the X.509 validity period model.
  • Common Event Format (CEF): Every secret operation (creation, access, rotation, deletion) is written to the audit trail and exported to SIEM systems in CEF format for correlation and compliance reporting.
  • Role-Based Access Control (NIST RBAC / INCITS 359-2012): Access to secrets is governed by a formal RBAC model with discrete permissions (read, write, rotate, delete, grant), supplemented by IP allowlists, time-window restrictions, and environment-boundary controls.

Getting Started#

  1. Inventory Credentials: Catalogue all existing credentials across your deployment for migration into the vault.
  2. Configure Access Policies: Define who can access, rotate, and manage secrets based on roles and responsibilities.
  3. Set Rotation Schedules: Establish appropriate rotation frequencies based on credential sensitivity and compliance requirements.
  4. Enable Monitoring: Configure expiration alerts, usage tracking, and SIEM integration for real-time visibility.
  5. Migrate Credentials: Import existing credentials into the vault and update consuming services to retrieve secrets from the centralised store.

Last Reviewed: 2026-02-05 Last Updated: 2026-04-14

Ready to Build?

Get started with our APIs or contact our integration team for support.