# Secrets management

> Keeping API keys, passwords and certificates out of code and chat — in a vault, rotated, access-logged — so one screenshot is not a breach.

A secret in source control is a secret on every laptop that ever cloned it, forever in history, searchable by bots that scan public repos within minutes. The vault exists so the credential lives in one place: environment injection at deploy, rotation on schedule, an audit trail of who read what.

The practical ladder: .env files are better than hardcoded secrets; a real vault or cloud secrets manager is better than .env; short-lived, identity-derived credentials beat stored ones. Wherever the ladder stops, rotation is the floor — a secret that never changes is a leak that has not happened yet.

## Related terms

- https://dfieldsolutions.com/en/glossary/encryption-at-rest.md
- https://dfieldsolutions.com/en/glossary/least-privilege.md
- https://dfieldsolutions.com/en/glossary/incident-response.md

---

Source: https://dfieldsolutions.com/en/glossary/secrets-management
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
