Dialed Vaultdialed vault

Rotate once.
Everywhere.

for Dialed and every client engagement

Every credential in one encrypted, audited place. Reveal a value in a click, always logged, then rotate it everywhere it's used. No redeploys, no chasing down copies.

Get startedExplore the vault
vault.dialed.dev
dialed vault
PROJECTS
Client Portal
Infra Tooling
Marketing Site
Mobile API
ORG
Audit log
Members & roles
Import / Export
Dialed /Client Portal /production
+ Add secret
⚠ PRODUCTION reveals require confirmation and are logged · dialed / client-portal / production · main
KEYVERUPDATEDREADABILITYVALUE
STRIPE_KEYv72d agoshared············reveal
DATABASE_URLv311d agoshared············reveal
SENDGRID_API_KEYv219d agoshared············reveal
JWT_SIGNING_KEYv51mo agoclient-only············reveal
S3_UPLOAD_SECRETv13mo agoshared············reveal
REDIS_URLv45d agoshared············reveal
rotation due: STRIPE_KEY in 12 days
dialed vault
Dialed/Client Portal/production
⚠ PRODUCTION
STRIPE_KEY
v7 · sharedreveal
DATABASE_URL
v3 · sharedreveal
SENDGRID_API_KEY
v2 · sharedreveal
JWT_SIGNING_KEY
v5 · client-onlyreveal
S3_UPLOAD_SECRET
v1 · sharedreveal
WHY DIALED VAULT

Built for how Dialed actually ships

Not a generic password manager. It's a credential system for a team running many client environments at once, self-hosted on infrastructure you control.

ENCRYPTION
Envelope encryption
AES-256-GCM per-secret keys, wrapped by your KMS. Ciphertext and keys never sit together.
ROTATION
Rotate once, propagate everywhere
Update in one place; every consumer picks it up. A checklist tracks every manual copy so nothing goes stale.
AUDIT
Tamper-evident audit trail
Every read, reveal, write, and rotation is logged and hash-chained. Auditors see metadata, never values.
ISOLATION
Hard multi-org isolation
Per-client orgs enforced at the database with row-level security, plus per-secret readability control.