Guide · 2026-08-24 · 3 min · by The SubScope team

How do you manage your API keys?

SOC 2 prep, a customer's security questionnaire, a due-diligence data room — the question always arrives eventually.

The question that always comes back

Every CTO eventually gets some version of “how do you manage your API keys and secrets” — in SOC 2 prep, a customer’s security questionnaire, or a due-diligence data room. The honest first-pass answer at most companies is some mix of “encrypted at rest, rotated when we remember, and Steve knows where most of them are.” That’s not a lie. It’s just not an answer anyone can act on, and it’s a bad moment to be improvising one.

Why this is a scaling problem, not a hygiene problem

At five engineers, credential sprawl is a Slack search away. At fifty, it isn’t. The number of credentials doesn’t grow linearly with headcount — it grows with every experiment, every vendor trial, every engineer who pastes a key into a Lambda because the secrets manager was one more step between them and a working demo. The problem was never that engineers are careless. It’s that nothing scales the accounting the way team size scales the sprawl.

What a real answer looks like — and what it doesn’t

Worth being precise here, since it’s easy to overclaim on a topic like this. SubScope doesn’t manage secrets on your behalf in the sense of rotating or revoking them for you — the one narrow exception is OpenAI, where a public leak triggers an automatic revoke via webhook. Everywhere else, the fix happens at the vendor’s own console, by a person, on purpose.

What it gives you for that question: a register of every credential across every vendor your teams have connected, an owner enforced at creation, staleness and zombie-key flags instead of “we think we deleted the old ones,” and an audit log of what changed and when. That’s something you can screenshot into a security questionnaire, not a promise you’re hoping holds up under a follow-up question.

The actual leverage

The value here isn’t any individual flag — it’s that ownership and staleness tracking happen without needing your personal attention. Accountability scales because it’s enforced the moment a credential is created, not because someone remembers to run an audit before the questionnaire is due. That’s the difference between a policy written down somewhere and a system that’s actually true when someone checks.

Governed

Filed under guide. Back to blog

Recommendation

Shrink your blast radius this week.

Connect one vendor. SubScope will show you what you have been trusting. Free during public beta.

Sign in Talk to us