Skip to main content
Treat every secret as if it’ll leak — design for that, and most leaks become non-events.

The rules

Never commit to source

.gitignore .env*. Use vly’s secret store.

Never expose to the client

Anything in process.env is server-only. Only VITE_* is client-visible.

Scope per environment

Test keys in preview/staging, live keys in production. No mixing.

Use least-privilege keys

A read-only key is much less dangerous if leaked.

Rotate quarterly

Even without suspected compromise. Cheap insurance.

Audit access

Review the audit log monthly for unexpected secret reads or changes.

Where vly stores secrets

In an encrypted secret store (AES-256), per-environment, accessible only to server-side code via process.env. See Deployment → Secrets for the operational details.

What to do if a secret leaks

  1. Revoke at the provider immediately.
  2. Generate a replacement.
  3. Update in vly’s secret store for affected environments.
  4. Audit downstream API logs for unexpected use.
  5. Notify users if data was at risk.

Deployment → Secrets

Operational reference.

Environment variables

The mechanism.

Audit logs

Track secret changes.
Last modified on April 18, 2026