Protect keys and secrets
Set a strong, unique master encryption secret for each Software Trust Manager deployment and store it in an approved secrets-management system — never leave it blank or reuse a default value.
Do not place credentials, database passwords, or the master encryption secret in configuration files under source control.
Rotate credentials and the master encryption secret according to your agency's policy and immediately upon suspected exposure.
Restrict access to keypair export approval, and review every export event.
Issue a dedicated client authentication certificate or API key per integration; do not share credentials across multiple automated clients.