Keyorix: Open-source secrets manager built for on-premise
Keyorix is a new open-source secrets manager designed to run completely on a company's own infrastructure. It is aimed at organizations that are not allowed, or do not want, to hand their credentials to a cloud provider.
For readers less familiar with the category, a secrets manager is a protected store from which applications pull the sensitive values they need to run, such as database passwords, API keys and access tokens. The point is to keep those values out of configuration files and source code, where they tend to leak. As a recent case showed, GitHub repositories still expose large numbers of valid credentials.
Keyorix is distributed as a single binary. In its core form, it does not need an internet connection at all.
Who it is for
The company behind the project, Keyorix SL, targets teams that cannot send secrets to a SaaS service. Two groups are named specifically: operators of air-gapped networks, which are isolated from the internet by design, and European enterprises that have to align with NIS2 and DORA.
NIS2 is the EU directive that sets cybersecurity requirements for organizations in critical and important sectors. DORA, the Digital Operational Resilience Act, covers the operational and ICT resilience of the financial sector.
Keyorix SL publishes its own comparison table that places the tool between two established options. One is Vault, which can run on premises but requires a dedicated administrator. The other is Doppler, which is described as simple to use but available only as SaaS. Keyorix positions itself as a self-hosted option that does not carry the operational weight of Vault.
Getting secrets into applications
Developers have two main ways to deliver secrets to their software. The first is a command-line tool that injects them as environment variables. The application then reads them like any other setting, without needing to know where they came from.
The second is a set of SDKs for Go, Python and Node.js, for teams that want to call the secrets store directly from code.
Organizations already running Vault can import their existing secrets into Keyorix. A single Docker Compose command brings up the full stack, including the web interface.
Access control and day-to-day management
Around the core store, Keyorix adds a layer of permissions and record keeping. The feature list includes:
- role-based access control and group permissions
- versioning of secrets
- separate development, staging and production environments
- service tokens for CI/CD jobs
- dashboard alerts for secrets that are close to a rotation deadline
Teams that prefer not to work from the command line can manage everything through a web dashboard.
How the data is protected
Every secret value is encrypted with AES-256-GCM. At startup, the operator sets a passphrase, which is stretched into a key-encrypting key. That key is held only in memory and is used to wrap the data key that actually encrypts the secrets.
For storage, Keyorix uses SQLite in development and for small teams, and PostgreSQL for production deployments.
Each access to a secret is recorded with details on who made the request, which secret was touched, when it happened and where the request came from. These records are kept across two separate audit layers.
Keyorix is available for free on GitHub.
Our Take
Keyorix arrives at a time when secrets handling is under more pressure than usual. Credentials keep turning up in public code, and CI/CD pipelines and automated tools increasingly need their own tokens. Our coverage of how AI agents keep data access after tasks end points to the same underlying problem: machine identities pile up, and someone has to track and rotate what they hold. Features such as rotation alerts, service tokens and detailed audit logs speak directly to that.
The regulatory angle also looks deliberate. For European firms working through NIS2 and DORA, being able to show where credentials live, who accessed them and when could be useful, and keeping everything on premises removes a third-party provider from the picture. That said, the pitch comes from the vendor, and the comparison against Vault and Doppler is the company's own. Teams should test those claims rather than take them at face value.
Self-hosting also moves responsibility back to the customer. The design keeps the key-encrypting key only in memory, which limits exposure on disk but also means the passphrase becomes a critical operational secret in its own right. Supply chain risk matters too, as incidents like the OpenInfra Europe Artifactory breach show for self-managed infrastructure.
It is worth watching whether Keyorix attracts independent security reviews, how quickly the project responds to reported issues, and whether Vault users actually take up the import path. Those factors are likely to decide whether it becomes a serious option for regulated and air-gapped environments or stays a niche alternative.
