Encrypted at Rest
All secrets encrypted with AES-256. Never stored in plain text, never logged.
Runtime Injection
Secrets are injected as environment variables when your service starts. No code changes needed.
Easy Rotation
Update secrets and redeploy with a single click. Zero-downtime rotation.
Reveal Protection
Secrets are masked by default. Reveal only when you need to, with audit logging.
Per-Service Scoping
Scope secrets to specific services. Each service only sees what it needs.
Always Free
Secrets management is included free with every plan. No limits on the number of secrets.
Manage secrets from the dashboard
Add, update, and remove secrets through the web UI. Values are masked by default and can be revealed on demand. Changes take effect on the next deploy.
- Add secrets via dashboard or CLI
- Masked by default, reveal on click
- Update and redeploy in one step
smll — secrets
$