🔐Encrypted vaultAES-256-GCM encryption with argon2id key derivation. Secrets never touch disk unencrypted.
🐚Shell-nativeShell hooks for bash, zsh, fish, nushell, and PowerShell that load and unload secrets automatically as you move between projects.
📋kredsfile.yamlA declarative manifest that defines what secrets a project needs. Safe to commit, easy to read.