Data classification

Credentials and Secrets

Credentials include passwords, API keys, OAuth tokens, certificates, and private keys. Vendors with access to credentials — identity providers, secret managers, and any service receiving API keys — carry critical security risk.

Risk profile

Compromised credentials are the leading cause of data breaches. Vendors handling credentials must maintain strong encryption at rest and in transit, strict access controls, comprehensive audit logs, and zero-knowledge architectures where possible.

Applicable frameworks

SOC 2ISO 27001FedRAMP

Example vendors

OktaAuth0HashiCorp Vault1Password Teams

Common questions

Should I store API keys in a SaaS secret manager or self-hosted?
Both are valid. SaaS secret managers (like HashiCorp Vault Cloud or AWS Secrets Manager) are convenient and well-audited. Self-hosted gives more control. The key requirements are encryption at rest, strict IAM, comprehensive audit logs, and HSM-backed key material.

Which of your vendors handle Credentials and Secrets?

TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.

Book a demo