Skip to main content

Protect keys and secrets

  • Set a strong, unique master encryption secret for each Software Trust Manager deployment and store it in an approved secrets-management system — never leave it blank or reuse a default value.

  • Do not place credentials, database passwords, or the master encryption secret in configuration files under source control.

  • Rotate credentials and the master encryption secret according to your agency's policy and immediately upon suspected exposure.

  • Restrict access to keypair export approval, and review every export event.

  • Issue a dedicated client authentication certificate or API key per integration; do not share credentials across multiple automated clients.