AyMINE | Company secret management

Business excelenece

Balance Scroecards
Task & Project Control

Interprocess management

System modules

Let us know what you're looking for

Do you prefer to ask us directly?

Call us +420 605 203 938 (the Czech Republic)

or use this contacts

Secret Management

Protecting credentials, login data, and other secrets within an organization requires end-to-end encryption tools

Security of Secret Protection

Organizations need to store various credentials, codes, and passwords. On one hand, they need to ensure maximum protection for them; on the other hand, their availability must not depend on a specific employee and must be accessible when needed.

Examples of Corporate Secrets
  • Credentials for company email accounts such as info@..., sales@..., etc.
  • Access credentials for managing all services and social profiles, e.g.:
    • Facebook account administrator
    • Access to the company Google account
    • Management of an external email server
  • Access to the corporate CMS for web management, LMS with internal courses, etc.
  • Dedicated system administrator accounts for SharePoint, AyMINE, etc.
  • Corporate server access credentials and certificates

The Necessity of End-to-End Encryption

All sensitive information within a company should be protected by end-to-end encryption. Sensitive information must never be placed on network drives or local employee drives without additional protection.
Cloud or internal services that lack built-in end-to-end encryption are also not secure storage options. These include SharePoint, Teams, and all DMS systems. (Services often offer an additional encryption option for a separate fee, but it is not a standard feature.)

What is End-to-End Encryption

End-to-End Encryption

End-to-end encryption encrypts data on your device, and it remains encrypted until it reaches another end-to-end encrypted destination capable of decrypting it. At no point between the endpoints can the data be accessed.

Fake End-to-End Encryption

Many services promise end-to-end encryption, but the mechanism does not actually protect the data at all times.

Examples of fake encryption:

  • There is a "backdoor" in the encryption mechanism, allowing the operator to decrypt it. Suspicions that Meta exploits this are repeatedly discussed.
  • A service claims end-to-end encryption, but means that transmission between your device and the server is encrypted, and then the data is encrypted on the server. This is how protection is provided by most cloud storage providers.
Risks Without End-to-End Encryption

Risks on Network Drives or DMS Without Encryption

If data is protected only by credentials, you have no control over who actually has access to it. Access rights can be changed temporarily to gain access to the data and then restored to their original state. Even if the change is logged, no one will ever notice without additional review. Access right changes occur regularly, making it easy for an extra change to get lost among them. And even if someone notices, it is easy to claim it was a mistake. How can that be disproved?

Network and server administrators have broad permissions in companies, but that certainly does not mean they should have access to all services. Furthermore, their accounts are the primary targets of external attacks. Therefore, a system administrator account should never have access to secrets unless strictly necessary.

Network drives can be compromised by a hacker. If credentials to other systems are stored on them, they can easily be exploited. You might not even know that the data has already been compromised.

Network drives are backed up and archived. Archives pose another risk because they are moved under the management of other administrators and can be attacked independently of the backed-up storage. Thus, each backup increases data risks.

Risks of Storing Secrets on Local Drives

Local hard drives on computers are even riskier than network drives. Network administrators (via remote management) and service technicians can gain access to these drives. Most computers end up in the hands of administrators—both internal and external—at least occasionally.

Deleting data when decommissioning a computer is not completely safe either. Although procedures and tools exist, control over how thoroughly the deletion was performed is usually minimal.

The security of local drives is generally even lower than that of network drives, partly because OS systems like Windows lack built-in isolation to prevent programs from accessing data outside their own directories.

Access Control to Secrets

A secret management tool ensures both the security of secrets and the control of access to them.

Basic Rules of Protection

  • Security is fully in the hands of the person responsible for the data. It must not depend on anyone else, such as an administrator or service provider.
  • You always have a full overview of who has access to the data. Ideally, you also have a complete history of who had access and when.
  • You can revoke access at any time.

Protection of Secrets in AyMINE and AySafe

For protecting secrets, AyMINE uses data vaults, which handle both encryption and access management. Access to a secret must be explicitly granted by its administrator. Furthermore, the administrator can only grant access to someone who has global permission enabled. Thus, an administrator cannot grant access to just anyone.

An administrator cannot do this by mistake. Unlocking a vault requires personal interaction, so the risk of error is minimal. (For details, see the description of data vaults.) Special vaults are used for storing secrets and are not used for anything else. Therefore, no one can accidentally gain access to credentials while being granted access to other classified or sensitive data.

Availability of Credentials

Interlinking with Records

AyMINE allows credentials to be linked to a variety of other records, such as:

  • Work procedures and business continuity plans
  • Orders and clients
  • Assets, e.g., information about servers and external services.

Credentials are thus very easy to find—they are attached to the records to which they pertain. However, this link does not reduce their protection in any way. An employee who has access to the main record does not automatically gain access to the credentials or other sensitive information. If they do not have access, they cannot even discover that credentials are attached.

Accessing Data

You can access secrets either directly from the main workspace (via the Secrets menu item) or from the detail view of the record to which the secret is attached. To gain access, you must always unlock your access wallet beforehand; otherwise, access cannot be granted.

Secrets can only be worked with on trusted devices. Without confirmation that the device is available and verified, secrets are never accessible.