Blog

Security guides for developers.

Practical writing on secret management, local-first software and keeping credentials under your control.

The onboarding and offboarding checklist every dev team skips

New hires need access fast and departing teammates need it revoked faster. Most teams have a process for one and not the other.

SSH keys 101: generating, storing and rotating them without losing your mind

A practical guide to managing SSH keys across servers, CI pipelines and teammates — without ending up with a key you can't account for.

Why we chose local-first encryption for Dotvault

How zero-knowledge architecture keeps your master password and secrets off our servers — and why that matters.

How to organise developer secrets without losing them

A practical system for storing API keys, SSH keys, environment variables and tokens so you can find them in seconds.

The hidden cost of scattered developer credentials

Why losing time to misplaced secrets is more expensive than it looks — and how to fix it.