Docs/Secrets/Concepts

Vault Hierarchy & Key Management Concepts

Understand how Vyntech Secrets structures cryptographic keys, organizational projects, environments, version histories, and access policies.

1. Four-Tier Resource Hierarchy

Vyntech Vault organizes secrets in a clean, isolated four-tier hierarchy to enforce least privilege access across infrastructure teams, developers, and CI/CD pipelines:

Level 1

Tenant Organization

The root multi-tenant container. Encrypted database pools and encryption master keys are strictly partitioned per tenant.

Level 2

Vault Project

Logical grouping of secrets belonging to a specific application, microservice, or infrastructure cluster (e.g. payment-service).

Level 3

Environment / Stage

Deployment targets such as production, staging, development, and ephemeral PR preview branches.

Level 4

Secret & Versions

Key-value pairs stored as immutable versioned records, with encrypted ciphertext, historical snapshots, and metadata comments.

2. Cryptographic Envelope Primitives

KEK

Key Encryption Key (KEK)

256-bit symmetric root key managed in kek_versions. KEKs are rotated independently of ciphertext, maintaining backward-compatible decryption across version epochs.

GCM

Galois/Counter Mode (AES-256-GCM)

Authenticated encryption ensuring both confidentiality and cryptographic integrity. Tampering with database ciphertexts causes immediate decryption authentication tag failures.

We use cookies and similar technologies to measure traffic and improve the site. You can choose which categories to allow. Manage Preferences.