What is new in SikkerKey
Product updates, security improvements, and platform changes. Subscribe to the feed to stay current.
RSS feedBring your own key, encrypt a vault with a key you control
Encrypt a vault with a key you hold in your own cloud KMS. Access runs through your own cloud console, so revoking it makes the vault unreadable until you restore access. Google Cloud KMS is supported today, with OVH, Scaleway, and AWS planned.
Read →Stronger isolation for the key that protects your secrets, plus reliability fixes
The root key that unlocks your secrets now runs on separate, isolated infrastructure, so a copy of the database alone can't be decrypted. Plus: removing a machine from a project is fixed, and our status page now reports webhook delivery.
Read →Alerts for blocked access attempts, plus security and reliability hardening
Connections from an IP outside your allowlist now show in your audit log and alerts. Plus single-use two-factor codes, stricter webhook delivery, canary tripwires and read limits that now cover bulk export, and more resilient managed-secret rotation.
Read →Full data erasure on vault deletion, plus security hardening
Delete a vault and your secrets, audit logs, and machine identities are now erased from production and backups within 30 days. Plus tighter browser security across the apps, abuse protection on single sign-on, and auto-clearing clipboard copies in SikkerLink.
Read →