{"id":457,"date":"2026-10-08T17:27:59","date_gmt":"2026-10-08T17:27:59","guid":{"rendered":"https:\/\/managedt.com\/blog\/keyorix-open-source-on-premise-secrets-management\/"},"modified":"2026-10-08T17:28:00","modified_gmt":"2026-10-08T17:28:00","slug":"keyorix-open-source-on-premise-secrets-management","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/keyorix-open-source-on-premise-secrets-management\/","title":{"rendered":"Keyorix: open-source on-premise secrets management for air-gapped and EU-regulated teams"},"content":{"rendered":"<p>Engineers and security teams who cannot send credentials to a cloud service now have a self-hosted option that fits in a single binary and needs no internet connection. Keyorix is an open-source secrets manager built for air-gapped networks and European enterprises that have to line up with NIS2 and DORA, the EU&#8217;s security and financial-resilience rules. Every secret value is encrypted with AES-256-GCM, access is logged across two audit layers, and a web dashboard handles day-to-day work.<\/p>\n<h2>What Keyorix is and who it is built for<\/h2>\n<p>A secrets manager is the locked store where an application fetches the database passwords, API keys, and tokens it needs, so they stay out of config files and source code. Keyorix is the open-source answer for teams that cannot point that store at a SaaS vendor.<\/p>\n<p>The company behind it positions the tool for two main cases: air-gapped networks that cannot reach a cloud service, and European enterprises that need to align with NIS2 and DORA. Its own comparison table sets Keyorix against two alternatives: Vault, which runs on premises but requires a dedicated admin, and Doppler, which is simple but SaaS-only. Keyorix sits in the middle, on premises, with no dedicated admin role required.<\/p>\n<h2>How secrets reach an application<\/h2>\n<p>Two delivery paths are offered. A command-line tool injects secrets as environment variables, so the application reads them like ordinary settings. Native SDKs are available for Go, Python, and Node.js for teams that want to call the store from inside the code.<\/p>\n<p>Migration is built in. Teams already running Vault can import what they have, and the full stack, web interface included, starts with one Docker Compose command. That low-friction start is part of the pitch to small teams that do not want a dedicated secrets administrator.<\/p>\n<h2>Access control, environments, and audit<\/h2>\n<p>Around the core engine sit the controls a security team expects:<\/p>\n<ul>\n<li>Role-based access control and group permissions.<\/li>\n<li>Secret versioning, so every change is tracked.<\/li>\n<li>Separate environments for development, staging, and production.<\/li>\n<li>Service tokens for CI\/CD jobs that need short-lived access.<\/li>\n<li>Dashboard alerts when a secret is nearing its rotation deadline.<\/li>\n<li>A web dashboard for teams that prefer a graphical interface over the command line.<\/li>\n<\/ul>\n<p>Every access is logged with who, what, when, and from where, across two audit layers. For regulated environments, that two-layer trail is the line item that maps to NIS2 logging expectations and DORA incident-response records.<\/p>\n<h2>How the encryption actually works<\/h2>\n<p>The cryptographic design is straightforward and worth understanding for compliance reviews. Each secret value is encrypted with AES-256-GCM. A passphrase is set at startup and stretched into a key-encrypting key that lives only in memory. That key wraps the data key, which in turn wraps the stored secrets. Keeping the key-encrypting key in RAM and never on disk is what lets the system run on hardware that may be seized or imaged.<\/p>\n<p>Storage is split by scale. SQLite backs development setups and small teams. PostgreSQL is the backend for production deployments where the audit and versioning features generate heavier write traffic.<\/p>\n<h2>Where to get it<\/h2>\n<p>Keyorix is available for free on GitHub under the project&#8217;s own organisation. The repository includes the single binary, the Docker Compose stack, and the SDKs for Go, Python, and Node.js. Because it is open source, teams in regulated environments can audit the code themselves before deploying it, which is often a hard requirement under NIS2 procurement rules.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is Keyorix?<\/h3>\n<p>Keyorix is an open-source secrets manager that runs entirely on a company&#8217;s own servers. It ships as one binary, needs no internet connection in its core form, and encrypts every secret with AES-256-GCM.<\/p>\n<h3>Who is Keyorix designed for?<\/h3>\n<p>It targets teams that cannot send credentials to a cloud service, including air-gapped networks and European enterprises aligning with NIS2 and DORA, the EU&#8217;s security and financial-resilience rules.<\/p>\n<h3>How does Keyorix deliver secrets to an application?<\/h3>\n<p>A command-line tool injects secrets as environment variables, and native SDKs are available for Go, Python, and Node.js. Teams already on Vault can import their existing data, and one Docker Compose command starts the full stack.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is Keyorix?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Keyorix is an open-source secrets manager that runs entirely on a company's own servers. It ships as one binary, needs no internet connection in its core form, and encrypts every secret with AES-256-GCM.\"}},{\"@type\":\"Question\",\"name\":\"Who is Keyorix designed for?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It targets teams that cannot send credentials to a cloud service, including air-gapped networks and European enterprises aligning with NIS2 and DORA, the EU's security and financial-resilience rules.\"}},{\"@type\":\"Question\",\"name\":\"How does Keyorix deliver secrets to an application?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"A command-line tool injects secrets as environment variables, and native SDKs are available for Go, Python, and Node.js. Teams already on Vault can import their existing data, and one Docker Compose command starts the full stack.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/10\/05\/keyorix-open-source-on-premise-secrets-management\/\" target=\"_blank\" rel=\"nofollow noopener\">helpnetsecurity.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Keyorix ships as one offline binary with AES-256-GCM encryption, RBAC, and a web UI, giving teams that cannot use SaaS a self-hosted vault.<\/p>\n","protected":false},"author":3,"featured_media":456,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-457","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/457","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=457"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/457\/revisions"}],"predecessor-version":[{"id":458,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/457\/revisions\/458"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/456"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=457"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=457"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=457"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}