Attach a policy to any vault secret: rotate every N days, warn before due, verify the new value against its provider before it goes live. AWS IAM keys and GCP service-account keys rotate automatically; LLM and GitHub tokens get a guided swap. Every version is kept, the previous one stays valid through a grace window, and a GitHub Action mirrors the new value into repository secrets.
Early access — turned on per workspace. Ask us to enable it for yours.
- Versioned secrets with a grace window and immediate revoke
- Automatic executors for AWS IAM and GCP service accounts
- Provider verification before the swap: LLM, GitHub, AWS, GCP
- Due and overdue notifications through Slack and signed webhooks