- Home
- Getting Started
- Account & Settings
- Roles & Add-On Access
- Settings
- Agentic
- White Label
- Agents & Engines
- Engines
-
Agents
- Overview
- Core Agents
- Core Agents
- Matrix Agent
- Audit Agent
- Industry Agents
- Patent Agent
- Add-On Modules
-
Manufacturing
- Manufacturing
- Overview
- Work Orders
- Production Scheduling
- Shop Floor Monitor
- OEE Dashboard
- Production Counters
- Plant & Process Setup
- Work Centers
- Bill of Materials
- Manufactured Products
- Work Instructions
- Quality Operations
- Overview
- Inspection Plans
- Quality Checklist
- Non-Conformance (NCR)
- SPC Charts
- Traceability (4M)
- Maintenance Operations
- Overview
- Asset Registry
- Preventive Maintenance
- Work Orders
- Spare Parts
- Reliability Dashboard
- Inventory Operations
- Overview
- Material Staging
- WIP Tracking
- Kanban Replenishment
- Material Consumption
- Assets
- Asset Health
- Legal
- Construction
- Government
- Education
- Energy
- Agriculture
- Healthcare
- RevOps
- Ecommerce Operations
- Financial Audit & Fintech Ops
- Insurance
- Hospitality
- Real Estate
- Patent & R&D Operations
- Automotive & Fleet Management Ops
- Customs & Global Trade
- Enterprise & Technical
-
Enterprise Operations
- Enterprise Operations
- Overview
- Enterprise Operations Guide
- Compliance & Docs
- Overview
- Approval Workflow
- Expiry Reminders
- Document Control
- Audit Trail
- Compliance Radar
- Contracts & Warranty
- Overview
- Active Contracts
- Warranty Check
- Service Billing
- Field Service
- Overview
- Dispatch Board
- Job Management
- Van Inventory
- Performance Dashboard
- Service Desk
- Overview
- Service Requests
- SLA Monitor
- Knowledge Base
- Procurement & Vendor
- Purchase Orders
- Vendor Portal
- RFQ Management
- QHSE
- Overview
- Incident Reporting
- Permit to Work
- Safety Inspections
-
Security & Compliance
- Threat & Monitoring
- Overview
- Security Hub
- Security Audit
- IAM Visualizer
- Dependency Scanner
- Secret Scanner
- Secret Vault
- Traffic Monitor
- Audit Trail
- Threat Simulator
- Compliance Radar (MatrixAgent)
- Identity & Compliance
- Overview
- PPTX Auditor
- PDF Auditor
-
Engineering & Infrastructure
- DevOps & Infrastructure
- Overview
- Cron Builder
- CI/CD Pipeline
- Containers
- Log Streamer
- Secrets Management
- Health Monitor
- Infrastructure as Code
- Developer Tools
- Overview
- Nerve Center
- Git Diff Viewer
- Regex Tester
- JSON Transformer
- Workflow Optimizer
- Execution Replay
- Workflow Editor
- Dev Hub Terminal
- Security Hub
- Graph View
- Terminal Editor
- API Playground
- DSL Compiler
- Database Tools
- Overview
- Database Manager
- ORM Mapper
- SQL Formatter
- Schema Visualizer
- Visual Query Builder
- Seed Data Generator
- Custom Collections
- QA & Test
- Overview
- Flake Tracker
- Artifact Vault
- Web Test Module
- Test Plan & Runner
-
Data & Intelligence
- AIOps & Intelligence
- Overview
- Agents
- Agent Architect
- Model Center
- Prompt Lab
- Knowledge Base
- Agent Persona Editor
- Tool / Function Registry
- Observability & Logs
- DataOps & Analytics
- Overview
- Data Inspector
- AI Predictive Models
- Core Modules
- Ads & Social Media
- AI Assistants
- API & Integration
- App Groups
- Appointment Booking
-
Automation
- Automation
- Overview
- Workflow Editor
- Monitoring
- Execution Heatmap
- Workflow Pulse
- Trigger Control
- Task Scheduler
- Integration Hub
- Rule Engine
- Pipeline Designer
- Workflow Editor
- Overview
- Triggers
- Manual Input
- Data Sources
- Ecommerce
- Document Management
- Logic & Transform
- AI Agents
- Knowledge / AI
- Validation & Security
- Integrations
- Outputs
- Document Generation
- Image Generation
- Video Generation
- Coming Soon
- Call Center
- Collaboration
- Community
- Creative Studio
- CRM
- Fleet & Logistics
-
Finance
- Hub
- Finance Hub
- Accounting Hub
- Treasury & Banking Hub
- Commercial Accounts Hub
- Invoicing & Billing Hub
- Reporting & Analytics Hub
- Grid View
- Overview
- Accounting AI Assistant
- Treasury
- Invoice Manager
- Expense Management
- Financial Accounts
- Payroll
- Accounts Receivable
- Accounts Payable
- Bank Reconciliation
- Budget & Forecasting
- Expenses & Budget
- Profit & Loss
- Tax & Compliance
- Galleries & Curation
- Google Display Ads
- Human Resources
- Legal & Support
- Logistics
- Map Explorer
- Marketing
- My Workspace
- Plans & Pricing
- Point of Sale
- Product Management
- Purchase
- Sales
- Semantic Search
- Strategy & Fundraising
- Warehouse
- Website
- Productivity
- Project Management
- Documents
- Learning (LMS)
-
Creator Tools
- Overview
- Brand Identity Creator
- Template Creator
- Image Creator
- Overview
- Getting Started
- Image Generation
- Remix
- Upscale
- Magic Replace
- Remove Background
- Reframe
- Describe
- Magic Tags
- Magic Fill
- Style Transfer
- Style Preset
- Social Media Images
- Prompting Guide
- Video Creator
- Overview
- Getting Started with Video
- Text to Video
- Image to Video
- AI Video Transition
- Video Effects
- Scene Builder
- Short Film Creator
- Audio Creator
- Overview
- AI Audio
- Text to Speech
- Voice Cloning
- Music Generation
- Sound Effects
- Writer Tools
- App Factory
- Research
- Utilities
Secret Vault
Encrypted secret store with environment namespacing, rotation policies, per-access audit logging, and CI/CD environment injection.
Overview
Secret Vault is TotalApp's built-in encrypted credential store. It gives developers a secure, centralised place to manage API keys, database passwords, tokens, and certificates — without storing them in source code, .env files committed to git, or plain-text configuration files.
Secrets are organised by environment (development, staging, production) and by project. Every read access is logged with a timestamp and actor identity so you have a full access history for compliance purposes.
Scope of Secret Vault
Secret Vault is designed as a developer-productivity layer within TotalApp. For production infrastructure-level secrets, continue using your cloud provider's secret manager (AWS Secrets Manager, GCP Secret Manager, Azure Key Vault). TotalApp's vault complements, not replaces, those systems.
Quick Start
- Open Secret Vault from the Security sidebar.
- Click New Secret. Enter a name, value, and select an environment (dev / staging / prod).
- Click Save. The value is encrypted at rest and never shown in plain text again — only masked (
••••••••). - To reveal a secret value, click the eye icon on the row. This action is logged.
- To rotate a secret, open the detail panel and click Rotate. Enter the new value and confirm.
Bulk import
Click Import .env to bulk-import secrets from an existing .env file. All key-value pairs are parsed and stored as individual secrets in the selected environment namespace.
Features
Encryption at Rest
All secret values are encrypted using AES-256 before storage. Keys are derived per-user so even a database dump reveals no plaintext credentials.
Environment Namespacing
Separate dev, staging, and prod namespaces prevent accidental use of production credentials in development. Each environment can be locked to specific user roles.
Rotation Policies
Set a rotation interval (30 / 60 / 90 days) on any secret. Vault sends a notification when a secret is approaching or past its rotation date.
Access Audit Log
Every reveal, copy, and rotation event is logged with the actor identity, timestamp, and IP address. Export the log as CSV for compliance reports.
CI/CD Injection
Reference vault secrets in your CI/CD pipeline using the $VAULT:secretName syntax. The TotalApp CI connector resolves references at pipeline start-time without exposing values in logs.
.env Import & Export
Import from an existing .env file or export all secrets in a namespace to a .env file for local development. Export always prompts for confirmation and is logged.
Secret Lifecycle
| State | What it means | Action available |
|---|---|---|
| Active | Secret is current and within rotation window | Reveal, Copy, Rotate, Delete |
| Rotation due | Secret has passed its rotation date | Rotate (highlighted), Reveal, Delete |
| Compromised | Manually flagged as potentially exposed | Rotate immediately, View access log |
| Retired | Replaced by a newer version after rotation | View value (read-only), Delete |
FAQ
/api/data/secret-vault), encrypted at rest using AES-256. The encryption key is derived from the authenticated user's session token and never persisted alongside the data.