Skip to main content

Secrets Management

practice

Secrets management is the controlled creation, storage, distribution, use, rotation, revocation, and auditing of sensitive credentials used by people, applications, and infrastructure.

Status: published
Last reviewed: 2026-09-12

Technical explanation

Secrets include passwords, API keys, tokens, certificates, and cryptographic keys. A secrets-management system centralises protected storage, authenticates workloads, issues narrowly scoped or dynamic credentials, limits exposure, records access, and automates rotation.

Business relevance

It reduces hard-coded credentials, uncontrolled copies, long-lived access, and incident-response delays. Strong secrets practices are essential for cloud infrastructure, APIs, automation, and CI/CD.

Implementation example

A deployment pipeline authenticates through workload identity and retrieves a short-lived database credential at runtime instead of storing a password in source code or environment files.

Limitations and common misconceptions

A vault is not sufficient if applications log secrets, identities are overprivileged, recovery is weak, or rotation breaks dependent systems. The management platform itself becomes a critical security dependency.

Discuss your systems

Need help implementing or evaluating this concept? Keenfunnel designs connected AI, automation, and data systems.

Book a discovery session