Vault Hierarchy & Key Management Concepts
Understand how Vyntech Secrets structures cryptographic keys, organizational projects, environments, version histories, and access policies.
1. Four-Tier Resource Hierarchy
Vyntech Vault organizes secrets in a clean, isolated four-tier hierarchy to enforce least privilege access across infrastructure teams, developers, and CI/CD pipelines:
Tenant Organization
The root multi-tenant container. Encrypted database pools and encryption master keys are strictly partitioned per tenant.
Vault Project
Logical grouping of secrets belonging to a specific application, microservice, or infrastructure cluster (e.g. payment-service).
Environment / Stage
Deployment targets such as production, staging, development, and ephemeral PR preview branches.
Secret & Versions
Key-value pairs stored as immutable versioned records, with encrypted ciphertext, historical snapshots, and metadata comments.
2. Cryptographic Envelope Primitives
Key Encryption Key (KEK)
256-bit symmetric root key managed in kek_versions. KEKs are rotated independently of ciphertext, maintaining backward-compatible decryption across version epochs.
Galois/Counter Mode (AES-256-GCM)
Authenticated encryption ensuring both confidentiality and cryptographic integrity. Tampering with database ciphertexts causes immediate decryption authentication tag failures.