hatchmoment. scored by care · not by stars

echo-vault

Secure, self‑hosted secrets vault with signed clients and tamper‑evident audit.

Echo Vault gives teams a lightweight, self‑hosted secrets manager that encrypts every secret version with AES‑256‑GCM and authenticates every request with a signed HMAC. It rejects replay attacks, tracks a tamper‑evident audit chain, and offers a browser console that keeps keys in memory only. Designed for developers and ops who want a small, inspectable system instead of a black‑box, it outperforms larger solutions by eliminating external dependencies and providing built‑in auditability. Ideal for CI/CD pipelines, micro‑services, and any environment where secret integrity and traceability matter.

aes-gcmdevopsfastapisecrets-managementsecurityself-hostedsqlitezero-trust
View on GitHub →

echoomegaprime/echo-vault