Cybersecurity Glossary

Secrets Management

Storing passwords, keys and tokens used by software in one protected place rather than in files and code.

What Secrets Management means

Applications need credentials, and those credentials end up in configuration files, scripts, chat messages and repositories. A secrets manager holds them centrally, hands them out at run time, records who fetched what and lets you rotate a key without hunting through the estate.

Why Secrets Management matters for small businesses and nonprofits

For a small team the risk is concentrated: one leaked file with a live key can expose a database or a payment integration. Rotating a credential you cannot find is impossible, which is why leaks stay live for years.

What to do about Secrets Management

Three steps to deal with Secrets Management

  • Search your repositories and shared drives for keys and tokens, and assume anything found is compromised
  • Move live credentials into a managed vault and give applications access rather than copies
  • Rotate anything that has ever been sent by chat or email

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.

Storing passwords, keys and tokens used by software in one protected place rather than in files and code.