This page describes how Smart Grow Vault ("Smart Vault") protects your data today, what it does not do, and how to report a vulnerability. We only describe controls that exist in the product. Security teams evaluating Smart Vault can ask for a more detailed technical overview at support@smart-grow.app.
1. Summary
- Your content is encrypted at rest, with a separate key for each organization.
- Requests that carry secrets travel inside a post-quantum encrypted channel, on top of HTTPS.
- Access is controlled by roles, per-environment permissions and scoped API keys.
- The CLI signs in with a device you approve, and each device proves its identity on every request.
- Individual changes to variables, and changes to files, apps, environments and members, are recorded in an activity log.
- We do not hold security certifications yet.
2. Encryption
2.1 In transit. All connections use HTTPS. Requests that carry secrets also travel inside an additional post-quantum encrypted channel: variables, secure files, API keys, CLI sign-in and downloads, and sensitive account operations. Before opening the channel, the web app checks the server's signing key against a key built into the app. Each encrypted message is bound to its exact request and is accepted only once, which blocks replays. Sign-in and other authentication requests use HTTPS.
2.2 At rest. Before we store a variable or a secure file, it is encrypted with a key derived for that record from your organization's key. The encryption is bound to the record's organization, environment and identity, so a stored value cannot be moved or swapped. Each organization has its own randomly generated key, which is stored encrypted with a master key kept in Cloudflare's secrets store.
2.3 What this means. The Service decrypts your content to answer requests that you or your team authorize, from the web app, the CLI or an API key. Smart Vault is not end-to-end or zero-knowledge encrypted: our infrastructure holds the keys needed to decrypt. Our staff do not access your content unless you ask for support that requires it or the law requires it.
2.4 Credentials. Passwords are stored as one-way hashes by our authentication system. API keys and CLI tokens are stored only as one-way hashes, so we cannot recover them. Two-factor secrets and backup codes are stored encrypted.
3. Access control
- Roles. Each organization has an owner, admins and members. Owners and admins manage the whole organization. Members only reach the apps and environments they are granted, with read or write permission. Anything not granted is denied.
- Owner-only actions. Only the owner can delete the organization, view the activity log and create API keys limited to that organization, its apps or its environments.
- Isolation. Every request is checked against organization membership and permissions, and each organization's content is encrypted with its own key.
- API keys. A key can be limited to an organization, app or environment. A key without a limit reads only what its creator can read. Keys carry read permissions for variables and files. Keys are used to download variables and secure files, for example in CI/CD. They expire after 90 days by default and can be deleted at any time. On every use we check that the key's owner is still a member with access to that environment. Each key has a monthly request quota and a per-minute limit set by the plan.
- Internal administration. Our administration tools require an administrator role, which is checked on every request.
4. Authentication
- Email verification is required before the first sign-in.
- Passwords must have at least 8 characters. Accounts created with email and password must also include letters and numbers.
- Social sign-in with Google, Microsoft, GitHub and GitLab.
- Two-factor authentication with an authenticator app and backup codes, for accounts with a password, and passkeys. Both are optional; we recommend them.
- Sessions expire after 7 days without activity. Signing in with a password ends your other sessions.
- CLI. The CLI creates a key pair on your device. You approve its sign-in code in the browser, where you can see the device's fingerprint. Every CLI request is then signed with that device key, so a copied token cannot be used from another machine. CLI sessions expire after 7 days, you can have up to 5 active devices, and you can revoke any of them from the web app.
5. Activity log
- What it records: creation, changes, deletion and rollback of variables; creation, changes and deletion of secure files, apps and environments; and changes to members' roles and permissions, and member removals. Each entry includes who did it, when, and the IP address and user agent.
- Who can see it: the organization owner.
- What it does not record yet: reads and downloads of secrets, bulk imports, API key changes, invitations and sign-ins.
6. Infrastructure and application security
- The Service runs on Cloudflare's network, which provides DDoS mitigation.
- Rate limits apply to every API route by IP address, with stricter limits on sign-in, CLI sign-in and write operations, and per API key.
- API responses carry strict security headers, cross-site requests are checked against our origin, and only our web app is allowed to call the API from a browser.
- Database queries are parameterized.
- Our structured logs remove fields such as passwords, tokens, keys and secrets. Unexpected errors return a generic message.
- Our database provider keeps point-in-time recovery data for up to 30 days.
7. Certifications
We have not completed any security audit or certification, such as SOC 2 or ISO 27001. This page describes the technical controls in the product; it is not a compliance statement. Our Privacy Policy explains how we handle personal data.
8. Incidents
If a security incident affects your personal data, we will notify you and the authorities as the applicable law requires.
9. Reporting a vulnerability
Email support@smart-grow.app with "Security" in the subject. Please include:
- the type of issue and the affected endpoint or component;
- steps to reproduce it;
- its potential impact.
Guidelines
- Test only against accounts and organizations you own.
- Do not access, modify or delete other people's data.
- Do not run denial-of-service tests, social engineering or spam.
- Give us reasonable time to fix the issue before you disclose it.
Our commitment. We will confirm that we received your report, keep you informed while we work on it, and credit you if you wish. We will not take legal action against good-faith research that follows these guidelines.
10. Your part
- Turn on two-factor authentication or add a passkey.
- Give members only the environments they need, and remove people who leave the team.
- Give API keys the smallest scope that works, keep them in your CI secret store, and delete the ones you no longer use.
- Review your CLI devices and revoke the ones you no longer use.
- Never commit the
.envfiles the CLI downloads.
11. Self-hosted edition
Your organization's data lives in your own database and is encrypted with keys you generate and keep. Smart Dev Agency has no copy of those keys and no access to the instance. The only connection to us is the license service: the instance activates once and then confirms its license about every 20 minutes. Those requests carry only the license and the instance's identifiers — never secrets, names or email addresses. If the license service can't be reached, the instance keeps working for 24 hours after its last confirmation expires; after that it answers every request with "license unavailable" until the connection is back or you activate a new license. It can't run fully offline. You are responsible for backups, keeping your encryption key safe and applying updates.