Professional Security
Armored Keys ⛨
Private keys. Off device. Under guard.
Keys move off-device.
No longer in .env.keys. Harder to leak. Harder to steal.
Grant decryption, not possession.
Private keys are retrieved only when an authorized workflow needs them. Used in memory, then gone — so developers, CI, and agents can decrypt without keeping long-lived keys on disk.