Infisical is the open source security infrastructure platform that teams use for secrets, certificates, and privileged access management.
We're on a mission to make security tooling more accessible to everyone, not just security teams, and that means redesigning the entire developer experience from ground up.
Features
Secrets Management:
Centralize your application secrets and configuration across every environment, with versioning, rotation, and leak prevention built in.
Dashboard: Manage secrets across projects and environments (e.g. development, production, etc.) through a user-friendly interface.
Infisical Agent: Inject secrets into applications without modifying any code logic.
Honey Tokens: Plant decoy credentials alongside your real secrets that act as tripwires, instantly alerting your team the moment an attacker tries to use them.
Agent Vault: Broker AI agent access to external APIs so agents never hold real credentials. Outbound requests route through a proxy that injects secrets before forwarding, eliminating credential exfiltration risk from prompt injection.
Certificate Management
Run a complete private PKI: issue, manage, and monitor X.509 certificates from a centralized platform.
Internal CA: Create and manage a private
CA hierarchy directly within Infisical.
External CA: Integrate with third-party certificate authorities such as Let’s Encrypt, DigiCert, Microsoft AD CS, and more to leverage existing PKI infrastructure
or issue publicly trusted certificates.
Alerting: Configure alerting for expiring CA and end-entity certificates.
Code Signing: Sign software artifacts like containers, installers, and packages with managed code-signing certificates, central approval, and a full audit trail.
Infisical Key Management System (KMS):
Centrally manage cryptographic keys and use them to encrypt and decrypt data across your projects.
Cryptographic Keys: Centrally manage keys across projects through a user-friendly interface or via the API.