Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. A secrets manager is the locked store where an application fetches the database passwords, API keys, and tokens it needs, so they stay out of config files and source code. It ships as one binary and, in its core form, needs no internet connection.

Keyorix

Keyorix SL, the company behind it, pitches that to teams that cannot send credentials to a cloud service, such as air-gapped networks and European enterprises that need to line up with NIS2 and DORA, the EU’s security and financial-resilience rules. The company’s own comparison table sets Keyorix against two tools: Vault, which runs on premises but requires a dedicated admin, and Doppler, which is simple but SaaS-only.

Developers get secrets into an app through a command-line tool that injects them as environment variables, so the app reads them like ordinary settings, or through SDKs for Go, Python, and Node.js. Teams already on Vault can import what they have, and one Docker Compose command starts the full stack, web interface included.

Around that core sit access controls and bookkeeping: role-based access control, group permissions, secret versioning, separate development, staging, and production environments, service tokens for CI/CD jobs, and dashboard alerts for secrets nearing a rotation deadline. A web dashboard serves teams that prefer a graphical interface.

Under the hood, every secret value is encrypted with AES-256-GCM. A passphrase set at startup is stretched into a key-encrypting key that lives only in memory, and that key wraps the data key. Data sits in SQLite for development and small teams or in PostgreSQL for production. Every access is logged with who, what, when, and from where, across two audit layers.

Keyorix is available for free on GitHub.

Must read:

Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!

Don't miss