About

Secrets shouldn't live in Git, Slack, or a spreadsheet

SnapEnv is one encrypted source of truth for environment variables and secrets — per project, per environment — with scoped access control and a complete audit trail.

The problem

Environment variables end up everywhere they shouldn't

Committed .env files. Secrets pasted into Slack. Values copy-pasted between servers by hand. Hardcoded credentials in CI config. Once that happens, nobody can say who has access to what, when a key was last rotated, or who pulled production secrets last week.

What SnapEnv does

Encrypted, delivered at runtime, never committed

Values are encrypted with AES-256-GCM before they're ever written to disk, using a key derived per-project via HKDF-SHA256 from a server-side master key. Decryption happens server-side only. Values reach your app through the CLI, the Kubernetes operator, the API, or CI integrations — whichever fits how you deploy.

terminal
# Pull secrets to .env
snapenv pull --env prod
✓ 14 variables written to .env

# Or inject directly into a process — nothing touches disk
snapenv run --env prod --only DATABASE_URL -- node server.js
Who it's for

Dev teams who want this without running it themselves

SnapEnv is built for teams who want centralized secrets without the overhead of operating a secrets engine. If you need dynamic secrets, PKI, or enterprise-scale vaulting, HashiCorp Vault does more. SnapEnv covers the common case — store, deliver, scope access, and audit — without that operational weight.

SnapEnv is a hosted service. There's no infrastructure to run yourself — sign up, invite your team, and connect the CLI or operator.

FAQ
Is SnapEnv self-hosted?

Not currently — SnapEnv is a hosted service. You sign up, invite your team, and connect the CLI or operator. There's no infrastructure to run yourself.

Who is SnapEnv for?

Dev teams and small platform/infra teams who want centralized, encrypted secrets without running a secrets engine themselves — from a solo project to a small Kubernetes-based platform team.

How is SnapEnv different from HashiCorp Vault?

SnapEnv covers the common case — storing and delivering environment variables with access control and an audit log — without Vault's operational overhead. If you need dynamic secrets or PKI, Vault is more powerful.

Try SnapEnv free

3 projects, 3 members, full CLI & Kubernetes operator. No credit card.