How does it fair against Vault? Vault is self hosted and open source.
Does everyone in this thread know the founder or something? No one is asking these and they're in my view the absolutely most important questions.
How does it fair against Vault? Vault is self hosted and open source.
Does everyone in this thread know the founder or something? No one is asking these and they're in my view the absolutely most important questions.
Then I looked at the API documentation and it seems, no, you're being encouraged to send your secrets verbatim over the Internet.
I understand how this invites comparisons with the CSP secrets management products (e.g. AWS Secrets Manager), but it seems strictly worse from a number of perspectives:
* blast radius: if I'm a multi-cloud, or hybrid-cloud, property then compromise of one environment doesn't necessarily lead to compromise of the others; if I have all my eggs in one basket, like Doppler, then it seems like it does.
* Internet traversal: if I'm using something like AWS Secrets Manager from within AWS, I can entirely avoid having to traverse the Internet for my secrets by using VPC endpoints. Having to cross the Internet just means I'm exposed to more bad actors, an increased variety of attacks and also operational risk factors unrelated to security.
* (probable/possible?) segregation of duties concerns: the design of products like AWS Secrets Manager means that some kind of active collusion across product teams within AWS is required to create inappropriate disclosures and to conceal that disclosure. If secrets management is the only product line, that seems less likely to be sustainable.
License the software, let me deploy and manage it.
Full disclosure: I'm the founder :)
It is different in at least one important way: secrets (Such as private keys) are used to secure things (Such as code, data, or conversations) and thus are usually given a higher security priority (Like much tighter access control).