Security notes for people shipping with keys.
API key leaks, supply-chain incidents, AI workflow risks, and practical architecture notes from the VaultProof team.
Latest briefing: exposed keys, agent workflows, and the path away from plaintext secrets.
Recent security writing.
Field guides and incident notes for teams trying to keep secrets out of repos, agents, CI, and runtime logs.
I leaked my API key. Now what? The 60-minute triage guide.
Bots find exposed keys in under 11 minutes. Here's exactly what to do in the first hour: revoke, check for damage, scrub git history, and make sure it cannot happen again.
read the guide -> ->How Cisco got hacked through a security scanner.
TeamPCP compromised Trivy, harvested credentials from CI/CD pipelines, then used them to breach Cisco. Here is the attack chain.
read the analysis -> ->The Trivy attack revealed a blind spot in every secrets manager.
Trivy silently harvested credentials from CI/CD pipelines. Secrets managers did not help. Here's what would have stopped it.
read the report -> ->How to secure your OpenAI API key in 2026.
OpenAI keys are trivially easy to scan. Bots find them in minutes. Here's how to actually protect yours.
read the guide -> ->Vibe coding is leaking your secrets. Here's the fix.
AI coding tools make building faster, but security is often an afterthought. The numbers are rough, and fixable.
read the article -> ->VaultProof vs Doppler vs HashiCorp Vault.
All three manage secrets. A comparison of architecture, pricing, developer experience, and trust models.
read the comparison ->