Secrets Manager

Secure data storage for access to applications and certificates. AES 256-GCM encryption. Free issuance and autoupdate of your Let’s Encrypt® certificates.

Advantages of Secrets Manager by Servercore

Get started
Free data encryption and secure retrieval

Data are encrypted using the secure AES 256-GSM block cipher algorithm with a cryptographic key hierarchy. When confidential data are retrieved, the service decrypts them and sends them to users via a secure TLS connection.

Easy certificate issuance and management

We’ll issue a Let’s Encrypt® certificate for you free of charge. DNS-01 validation will be performed automatically.

Autoupdate of Let’s Encrypt® certificate

We’ll automatically initiate the update 30 days before your certificate expires. You won’t need to take any action.

Instantly update passwords anywhere

If you need to change your passwords for any reason, you don’t have to update them everywhere. Just update the information in our service. All applications using secrets manager will automatically import the new passwords and login credentials.

Centralized storage for passwords, certificates, and keys

All passwords, keys, and certificates are kept in a single repository. This will enable you to streamline their administration and minimize the risk of information leaks.

High service availability

Secrets manager nodes are distributed across multiple pools, allowing the service to continue operating even if one part fails.

Action history recording

For your convenience, every interaction with the service is recorded in the activity log, ensuring transparency. You can track the actions performed by other users in your corporate password manager. Events related to creation, reading, and deletion are available.

What You Can Store in Secrets Manager

Secrets

No longer need to store application access data in your code. Keep them in our secure online password vault. The service is perfect for storing logins, API keys, and any other sensitive and private info.

Certificates

We’ll issue and automatically update Let’s Encrypt® certificates free of charge. We’ll ensure regular DNS domain verification.
You can add TLS certificates obtained from any certification authority to the repository. After that, they’ll be shared across Servercore services and accessible in any of them.

Security of Servercore Solutions and Data Protection

5-tier IT system and data protection strategy

We ensure information security measures at all levels of data access — from application to data center.

Compliance with industry, local, international standards

Our solutions comply with standards ISO, PCI DSS, GDPR, DPA 2019, as confirmed by relevant certificates.

4 availability zones in 3 countries

Deploy services across several data centers located in Kenya, Uzbekistan or Kazakhstan to enhance the fault tolerance of your IT systems.

Servercore is Stable, Simple, and Offers Local Infrastructure

Request a consultation
01
Secured technologies

IaaS и PaaS

A wide range suitable for any task

Availability zones in Kenya, Uzbekistan, and Kazakhstan​

IAM service for managing authorization and access levels

02
Stability

SLA up to 100%

Maximum server availability

Compliance with GDPR and DPA 2019

Processing of personal data

PCI DSS

Payment data under protection
03
Benefit and convenience

Free migration

Billing in Kenyan shillings

Payment by MPesa or bank transfer

24/7

Free technical support

Businesses of All Sizes Trust Our Service Quality

Read case studies
Read case studies

Choose the Region Where You Want to Deploy Your Service

Nairobi
Almaty
Tashkent
1 availability zone
TIER III Design
TIER III
ISO27001
PCI DSS
Nairobi
Kenya
  • Dedicated Servers
  • Cloud Servers
  • Cloud Databases
  • Managed Kubernetes
1 availability zone
TIER III Design
TIER III Facility
ISO14001
ISO20000
ISO9001
ISO27001
ISO45000
Almaty
Kazakhstan
  • Dedicated Servers
  • Cloud Servers
  • Cloud Databases
  • Managed Kubernetes
1 availability zone
2 availability zone
3 availability zone
Reliability level — N+1
TIER II
Tashkent
Uzbekistan
  • Dedicated Servers
  • Cloud Servers
  • Cloud Databases
  • Managed Kubernetes
TIER III
Tashkent
Uzbekistan
  • Dedicated Servers
  • Cloud Servers
  • S3
  • Managed Kubernetes
Reliability level — N+1
TIER II
Tashkent
Uzbekistan
  • Dedicated Servers
  • Cloud Servers
  • Cloud Databases
  • Managed Kubernetes

Tier III data center in Nairobi

Fault tolerance level of at least 99.982% (no more than 95 minutes of downtime per year). Hosted services remain operational even during scheduled maintenance or power outages.

Compliance with global and local security standards

The data centers hosting Servercore products comply with DPA 2019 and GDPR standards and are PCI DSS 4.0.1 certified.

Five levels of client data protection

We ensure security of projects at all levels, from data centers to apps, through a range of measures, including 24/7 video surveillance, 2FA, encryption, and more.
Go to control panel

Work from User-Friendly Control Panel

All projects on a single screen with fast navigation
IAM service for managing access levels
Transparent billing with ready-to-use reports
24/7 support in English
Rapid resource scaling
All projects on a single screen with fast navigation
All resources of your infrastructure are consolidated in a single screen. Monitor projects directly from the home screen and navigate to the required section with one click.
IAM service for managing access levels
Configure resource access levels for each employee based on their role. This enhances the security of your IT infrastructure.
Transparent billing with ready-to-use reports
Pay only for the resources you use in local or foreign currency. Export detailed cost reports in just a few clicks.
24/7 support in English
When technical or organizational issues arise, our specialists are ready to provide prompt support. Average response time in chat after creating a ticket is 15 minutes.
Rapid resource scaling
Flexibly scale the compute capacity of your project with just a few clicks. Reduce consumption to optimize costs or increase capacity for new tasks.

Compatible Products and Services for More Efficient Work

Request a consultation

FAQ

What is a secrets manager?

Secrets manager is a free, unlimited web-based vault for user logins, certificates, API keys, and other passkeys used for authentication and signing in. The service allows you to automatically update secret data in all integrated applications on any device.

How does secrets manager ensure data protection and decryption?

Secrets manager uses the well-tested AES 256 block cipher algorithm to protect your organization’s data. Encryption occurs before the information is stored on a disk using a hierarchy of cryptographic keys.

DEK is an AES 256-GCM symmetric key used for data encryption. KEK is a key designed to encrypt the DEK key, also known as the master key. The full master key is not stored and exists only in RAM using Shamir’s Secret Sharing Scheme for enhanced security. Encrypted DEK keys protected with the KEK master key, are stored separately.

To decrypt the data, the service must first decrypt the DEK key using the master key, then use that key to decrypt the data itself. When retrieving sensitive information, secrets manager decrypts the data and transmits them to the user’s local environment via a secure TLS connection.

Is there a limit to the amount of information stored in secrets manager?

No, our password manager allows you to store and safely manage an unlimited number of keys, passwords, and certificates for your company.

How does the domain rights verification process work?

The DNS-01 validation process is automated. The domain DNS record data remains stored in Servercore’s infrastructure, allowing the secrets manager to independently generate a TXT record for certificate issuance.