The rules
Never commit to source
.gitignore .env*. Use vly’s secret store.Never expose to the client
Anything in
process.env is server-only. Only VITE_* is client-visible.Scope per environment
Test keys in preview/staging, live keys in production. No mixing.
Use least-privilege keys
A read-only key is much less dangerous if leaked.
Rotate quarterly
Even without suspected compromise. Cheap insurance.
Audit access
Review the audit log monthly for unexpected secret reads or changes.
Where vly stores secrets
In an encrypted secret store (AES-256), per-environment, accessible only to server-side code viaprocess.env.
See Deployment → Secrets for the operational details.
What to do if a secret leaks
- Revoke at the provider immediately.
- Generate a replacement.
- Update in vly’s secret store for affected environments.
- Audit downstream API logs for unexpected use.
- Notify users if data was at risk.
Related
Deployment → Secrets
Operational reference.
Environment variables
The mechanism.
Audit logs
Track secret changes.
