Secrets shouldn't live in Git, Slack, or a spreadsheet
SnapEnv is one encrypted source of truth for environment variables and secrets — per project, per environment — with scoped access control and a complete audit trail.
Environment variables end up everywhere they shouldn't
Committed .env files. Secrets pasted into Slack. Values copy-pasted between servers by hand. Hardcoded credentials in CI config. Once that happens, nobody can say who has access to what, when a key was last rotated, or who pulled production secrets last week.
Encrypted, delivered at runtime, never committed
Values are encrypted with AES-256-GCM before they're ever written to disk, using a key derived per-project via HKDF-SHA256 from a server-side master key. Decryption happens server-side only. Values reach your app through the CLI, the Kubernetes operator, the API, or CI integrations — whichever fits how you deploy.
# Pull secrets to .env snapenv pull --env prod ✓ 14 variables written to .env # Or inject directly into a process — nothing touches disk snapenv run --env prod --only DATABASE_URL -- node server.js
Dev teams who want this without running it themselves
SnapEnv is built for teams who want centralized secrets without the overhead of operating a secrets engine. If you need dynamic secrets, PKI, or enterprise-scale vaulting, HashiCorp Vault does more. SnapEnv covers the common case — store, deliver, scope access, and audit — without that operational weight.
SnapEnv is a hosted service. There's no infrastructure to run yourself — sign up, invite your team, and connect the CLI or operator.
Is SnapEnv self-hosted?
Not currently — SnapEnv is a hosted service. You sign up, invite your team, and connect the CLI or operator. There's no infrastructure to run yourself.
Who is SnapEnv for?
Dev teams and small platform/infra teams who want centralized, encrypted secrets without running a secrets engine themselves — from a solo project to a small Kubernetes-based platform team.
How is SnapEnv different from HashiCorp Vault?
SnapEnv covers the common case — storing and delivering environment variables with access control and an audit log — without Vault's operational overhead. If you need dynamic secrets or PKI, Vault is more powerful.
Try SnapEnv free
3 projects, 3 members, full CLI & Kubernetes operator. No credit card.