Do you keep your API keys and other sensitive data in the git repo as well, visible to all git contributors regardless of their credential level?
Who has access to each client's database? Is it audited? Is it encrypted at rest? I'm sure it is, but Config.ly would be wise to add this information to avoid fears.
Also you can store encrypted secrets in Git just fine, there are a number of methods to do so very safely.
https://docs.travis-ci.com/user/environment-variables/#defin...
> Who has access to each client's database? Is it audited? Is it encrypted at rest? I'm sure it is, but Config.ly would be wise to add this information to avoid fears.
This is great feedback, thank you.
You’re able to guard secretes as need, but keep the audit-ability of version control.