Professional Security

Armored Keys ⛨

Private keys. Off device. Under guard.

Keys move off-device.

No longer in .env.keys. Harder to leak. Harder to steal.

Grant decryption, not possession.

Private keys are retrieved only when an authorized workflow needs them. Used in memory, then gone — so developers, CI, and agents can decrypt without keeping long-lived keys on disk.

Grant this decryption?

Command
dotenvx run -- npm start
Location
Near San Francisco, California, United States
Device
MAC_OS_X

Armored keys.
Under guard.