Secrets management for application teams
Keel keeps application secrets in one encrypted workspace, grouped by project and environment, so the people and services that need a value can get it and nobody else can.
The problem Keel solves
Most teams start with a .env file and a shared message thread. That works until someone leaves, a laptop is lost, or a value changes and half the team keeps running the old one. Secrets end up in repositories, screenshots, CI settings, and personal notes, with no record of who has what.
Keel replaces that sprawl with a single system of record. Each project holds its secrets per environment, every change is versioned, and access is decided by role rather than by who happened to receive a copy.
How secrets are stored
- Secret values are encrypted at rest with AES-256-GCM. Each value gets its own random nonce and an authentication tag, so tampering is detected on read.
- The encryption key is supplied by the server environment and is never written to the database.
- Values are decrypted only after the request passes project role and environment access checks.
- Revealing a value and exporting an environment are recorded in the audit log.
How teams use it
- Create a project and choose who can access it.
- Add secrets to the Development, Staging, and Production environments, or import an existing .env file.
- Invite teammates with the role that fits: owner, admin, member, or viewer.
- Change values when you need to. Earlier values stay available through version history.
What Keel does not do yet
Being clear about limits matters for a security product. Keel does not currently rotate secrets automatically, does not issue machine or API credentials separate from user accounts, and does not use an external KMS or HSM. The encryption key is held by the server environment.
Frequently asked questions
- Where are secret values stored?
- In the Keel database as AES-256-GCM ciphertext. The encryption key is provided by the server environment and is not stored alongside the data.
- Who can read a secret?
- Only project members whose role allows reading secrets and who have access to that environment. Members and viewers need an explicit environment grant.
- Does Keel rotate secrets for me?
- No. You change a value yourself and Keel keeps the previous versions. Automatic rotation is not available.
Keep reading
- What is secrets management? A practical guide for developersSecrets management is how you store, distribute, and control access to credentials such as API keys and database passwords. Here is what it covers and where to start.
- How to store API keys securely in a web applicationWhere API keys should and should not live in a web application: server-side storage, browser limits, build-time pitfalls, and what to do when a key is exposed.
- Environment variablesSeparate Development, Staging, and Production values, with .env import and export.
- Access controlOwner, admin, member, and viewer roles, plus explicit per-environment grants.