A secret in source control is a secret on every laptop that ever cloned it, forever in history, searchable by bots that scan public repos within minutes. The vault exists so the credential lives in one place: environment injection at deploy, rotation on schedule, an audit trail of who read what.
The practical ladder: .env files are better than hardcoded secrets; a real vault or cloud secrets manager is better than .env; short-lived, identity-derived credentials beat stored ones. Wherever the ladder stops, rotation is the floor — a secret that never changes is a leak that has not happened yet.
Related terms
Encryption at rest
Encrypting data where it is stored — disks, databases, backups — so a stolen drive or leaked dump is ciphertext, not data.
Least privilege
Every user, service and process gets only the access the job requires — nothing more, so a compromise has a small blast radius.
Incident response
The plan and the practice for what happens between noticing something is wrong and being back to normal.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
