How do you manage your API keys?
SOC 2 prep, a customer's security questionnaire, a due-diligence data room — the question always arrives eventually.
The question that always comes back
Every CTO eventually gets some version of “how do you manage your API keys and secrets” — in SOC 2 prep, a customer’s security questionnaire, or a due-diligence data room. The honest first-pass answer at most companies is some mix of “encrypted at rest, rotated when we remember, and Steve knows where most of them are.” That’s not a lie. It’s just not an answer anyone can act on, and it’s a bad moment to be improvising one.
Why this is a scaling problem, not a hygiene problem
At five engineers, credential sprawl is a Slack search away. At fifty, it isn’t. The number of credentials doesn’t grow linearly with headcount — it grows with every experiment, every vendor trial, every engineer who pastes a key into a Lambda because the secrets manager was one more step between them and a working demo. The problem was never that engineers are careless. It’s that nothing scales the accounting the way team size scales the sprawl.
What a real answer looks like — and what it doesn’t
Worth being precise here, since it’s easy to overclaim on a topic like this. SubScope doesn’t manage secrets on your behalf in the sense of rotating or revoking them for you — the one narrow exception is OpenAI, where a public leak triggers an automatic revoke via webhook. Everywhere else, the fix happens at the vendor’s own console, by a person, on purpose.
What it gives you for that question: a register of every credential across every vendor your teams have connected, an owner enforced at creation, staleness and zombie-key flags instead of “we think we deleted the old ones,” and an audit log of what changed and when. That’s something you can screenshot into a security questionnaire, not a promise you’re hoping holds up under a follow-up question.
The actual leverage
The value here isn’t any individual flag — it’s that ownership and staleness tracking happen without needing your personal attention. Accountability scales because it’s enforced the moment a credential is created, not because someone remembers to run an audit before the questionnaire is due. That’s the difference between a policy written down somewhere and a system that’s actually true when someone checks.