Vaultic

Welcome to Vaultic

Encrypted, versioned secrets management for teams — a CLI, a web dashboard, and a server you run yourself.

Vaultic stores your app's secrets outside your codebase, injects them into local dev and CI without ever writing them to disk, and gives your team one place to see who changed what and when. Most teams have a first secret injected into a running process in under five minutes.

What Vaultic does

Versioned, encrypted secrets

Every write is a new version — old ones stay fetchable. Values are envelope-encrypted (AES-256-GCM) and masked everywhere except an explicit, separately-audited reveal.

Environments with inheritance

dev-alice can fall through to development for anything it doesn't override. env promote diffs and copies changes up a chain, e.g. staging → production.

Built for local dev and CI

vaultic run -- <cmd> injects secrets as env vars into a subprocess — nothing touches disk. vaultic export --check fails a CI job when a local .env drifts from the server.

A dashboard for everything else

The environment matrix, locked-environment change approvals, member roles and access grants, webhooks, secret trash, and Secrets Health.

Automation hooks

  • Webhooks — HMAC-signed generic JSON, or Slack-formatted, for the full write/rotation/ lifecycle event catalog.
  • Push to third parties — vaultic push github and vaultic push vercel sync an environment's secrets outward on demand.
  • Cloud secret store sync — push to AWS Secrets Manager, AWS SSM Parameter Store, GCP Secret Manager, or Azure Key Vault, either on demand (vaultic push <target>) or automatically from the web app every time a secret changes.
  • Ephemeral preview environments — a Git webhook auto-spawns a preview-<branch> environment per PR branch and tears it down when the branch is deleted.
  • Provider-assisted rotation — secrets rotate --provider <name> runs the actual credential rotation server-side (postgres, mysql, redis, aws-iam, cloudflare, gitlab, or a generic webhook), then stores the result through the normal versioned-write path.

See Automated syncs and Cloud secret store sync for the outbound integrations, and Terraform / Kubernetes for infrastructure-side reads.

Getting a server to talk to

The CLI and web app both need a Vaultic server to point at — your own self-hosted instance, or one your team already runs. This site documents how to use the CLI and the web app once you have a server; it's not a self-hosting guide.

On this page