Advanced › Security
Security
How your secrets are protected, and what you can do to keep them safe.
How Smart Vault protects them
Values are encrypted before they are stored, with a key for each organization. Requests that carry them travel through a post-quantum encrypted channel on top of HTTPS, and after you sign in, the CLI signs every request with its device key. API keys used in CI are not tied to a device, so keep them in your CI's secret store. The Security Policy has the details, including what Smart Vault does not do.
Recommendations
- Turn on two-factor authentication or add a passkey.
- Give members only the environments they need, and remove people who leave the team.
- Create one API key per pipeline, with read access only, and delete the ones you no longer use.
- Add
smart-grow.envto your.gitignore, and never commit it.