Infisical Secret Management logo

    Infisical Secret Management

    Sold by
    Infisical is the leading platform for developers to securely manage application configuration and secrets across their team and infrastructure. Used by Fortune 500 enterprises, international governments, and fastest-growing startups. With Infisical, you can save time for your engineering teams and enhance organization-wide security posture.

    Ratings and reviews

    4.5
    18 ratings
    3 star
    2 star
    1 star
    67%
    33%
    0%
    0%
    0%
    4 AWS reviews
    |
    14 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (18)
    Daniel Odeh

    Centralized secret management has streamlined daily operations but still needs automation features

    Reviewed on Jul 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We use Infisical to manage secrets day-to-day, currently hosting it on our machines in our offices. Since secrets are something very vital to us, we need somewhere to store secrets securely, and that's why we are using it. Applications need secrets. Applications have APIs and certificates, so day-to-day we use the service to get our secrets and to rotate secrets. That's what we use it for. We use Infisical internally in my company.

    What is most valuable?

    I think the core functionality or feature of saving secrets is the most valuable aspect of Infisical. It also has the organogram of how it was designed, where one could have multiple organizations. In each organization, you could have different projects, and in these projects, you could have different environments. This gives it the flexibility to have as many secrets as you could have for different organizations if you're working on a large or enterprise company. It also helps with sharing secrets. In our company, we use Kubernetes, so one can fetch these secrets from Infisical and then put them into the Kubernetes cluster. That feature is really nice. Additionally, one could rotate the secrets because you're not expected to store the same secret for a very long time, making it dynamic. It also has an audit trail of what is happening with the secret, including who changed what at what time. The core functionality for me is really what makes it amazing.

    Real-time monitoring and alerts with Infisical do help improve our response times to incidents. We've not really had any incidents at all, but it really helps with alerts and monitoring, of course.

    Since starting to use Infisical in my company, the overall positive impact includes saving time for developers who might otherwise try to save secrets somewhere. When someone comes in, you need to share the secret with them. Infisical has saved engineering time where a developer or someone needing a secret, certificate, or API key knows there is a specific place to go. Everything is organized in a hierarchy.

    What needs improvement?

    Unfortunately, we don't use Infisical's automated key rotation. For now, we rotate the secrets ourselves.

    We've not tried to improve Infisical, so I don't know if there are enhancements planned. We aim to explore using it with AI models and HCP server features implementation with Infisical. We consider having an agent that generates secrets instead of doing it manually. If a file or a secret is needed, the agent might generate it for us based on a specified pattern for the kind of secrets we want, including the length. This would be efficient, as we want to save engineering time. For example, with certificate keys already generated, we currently have to manually copy and put them into the Infisical UI. If an agent could handle that for us, it would be great.

    For how long have I used the solution?

    For close to three years now, I've been working with Infisical.

    What do I think about the stability of the solution?

    My evaluation of the reliability and stability of Infisical thus far is positive. It has been reliable and stable for us, and we've not experienced issues scaling or moving to a new image. It does not require many resources. Since we haven't had high resource utilization from end users, we can't determine its full reliability for extensive demands, such as if 20,000 or 50,000 people try to access our instance. Right now, we are quite small, and it's serving our needs without any downtime. It has been highly available since we brought it up. So, for our use case, it's acceptable.

    What do I think about the scalability of the solution?

    Infisical is currently scalable for us because of its design in the Kubernetes cluster. However, I can't give it a 100% rating for scalability since, as a startup, we've not had a large number of users putting it under heavy load, nor have we scaled it to more than two or three pods or instances. For our current use case, it's quite okay since we don't have many engineers, and it's heavily utilized by the Kubernetes cluster, resulting in considerable resource utilization.

    How are customer service and support?

    We don't have access to their technical support or customer service.

    I use the documentation available on GitHub and their website for Infisical. The documentation is great, and we follow those resources. When we encounter issues with the services, we often use AI to help resolve those issues, so we've not really needed additional support.

    Which solution did I use previously and why did I switch?

    Before Infisical, I was using HashiCorp Vault for the same use cases. However, the company tried to save on costs due to the license for HashiCorp Vault, which is why we moved to open source.

    How was the initial setup?

    The initial setup process for Infisical involved using their documentation and Kubernetes. They offer a Kubernetes manifest that you can utilize, making it quite easy to set up. Everything is already packaged in the service or image for Infisical, including PostgreSQL, and you just need an external database. We had it up and running in a day, so it was not a difficult task.

    What about the implementation team?

    I participated in the initial setup of Infisical as the lead engineer.

    Which other solutions did I evaluate?

    I was actually the one that kind of pushed for Infisical. When I conducted research, I found it was the only open-source solution that stood out. There are other open-source options, but I can't really remember their names. To harness the full capabilities of those services, however, you often need to pay. My company is a startup, so they're primarily focused on cost-saving, which is why I advocated for Infisical.

    What other advice do I have?

    I would evaluate Infisical's integration with our existing workflows as great. I think systems have to be simple and just do one thing. It really integrates well because we just have to put the secret variable or whatever it is in our code, and since the Kubernetes operator for Infisical is in our cluster, it knows where to get our secrets. I think it really fits well for our use case, actually.

    The capability of Infisical to manage secrets across our cloud and on-premises environments is primarily important for us. It's very key because if anyone has your secret, then they could access different systems in an organization. The capabilities in Infisical are really nice, featuring great functionality with what's already done there. It's very, very important at this point. We really can't do without it because of how vital it is for us in managing our secrets. We're not just talking about secrets; we are also discussing certificates, API keys, or anything that shouldn't be exposed to the public. It has this access control where you could determine who can see what and who shouldn't see certain information. At this point in time, it's one of our primary services that we use in the company and we can't do without it.

    We have seen a reduction in human errors with Infisical's customizable access policies. The policy helps, but we have encountered issues with newbies who join the company and haven't fully onboarded. This results in developers trying to push secrets to just the Git repository. Those cases are not really an Infisical issue, but we're trying to see how to ensure developers don't expose secrets. For now, it's manageable, but we could still have edge cases where someone doesn't know what's happening and exposes a secret to the repository. Unfortunately, we don't have a secret scanning feature in our Bitbucket repository, which is the only edge case. Otherwise, the policies are already in place, and they really help.

    I would rate this product a 7 overall.

    reviewer2870445

    Centralized secret management has streamlined deployments and improves team collaboration

    Reviewed on Jul 09, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Infisical consistently for the past couple of years in my current company. The main use case of Infisical is to manage our secrets. We use it to properly manage application secrets and environmental variables across development, staging, and production, replacing hard-coded secrets and .env files with a centralized, secure secrets manager for .NET, Node.js, or AWS workloads. Our main use case is secure secret management, environmental variable management, and syncing it with any other Vercel or cloud deployment that we use.

    How we use it depends on the particular applications in the first place. Technically, we use Infisical to securely manage secrets for our AWS-hosted applications. During CI/CD deployments, our GitHub Actions pipelines retrieve environment-specific secrets such as database connection strings, JWT signing keys, and third-party API credentials like Knovo, Twilio, or Resend from Infisical and inject them into the applications at deploy time. This keeps secrets out of the codebase and avoids storing them in repository or pipeline variables.

    For AWS Lambda specifically, our AWS Lambda functions retrieve their configurations and secrets from Infisical during deployment. This allows us to maintain separate secrets for development, staging, and production while ensuring sensitive values such as database credentials and API keys are never committed to source control.

    What is most valuable?

    There are a bunch of features that we are using right now. The best features are centralized secret management, environmental separation, and secret versioning.

    Centralized secret management makes day-to-day development much easier because everyone works from a single source of truth. Developers do not need to request secrets from teammates or keep local .env files in sync because we do not push our .env files to our GitHub. We manage separate secrets for development, staging, and production, and access is controlled through roles, so each person only sees what they need. When it comes to secret versioning, it is useful when rotating credentials or updating configuration. If a new secret causes an issue after deployment, we can quickly see what changed and roll back to a previous version instead of manually tracking all values.

    One of the best features I find very useful is that it is hosted and everyone who has access can easily access it and update it accordingly. Infisical has significantly improved our security posture by giving us a centralized and controlled way to manage application secrets. Previously, managing environmental variables across multiple services and environments became difficult, especially when teams needed to share or rotate credentials.

    From a productivity perspective, developers spend less time requesting, locating, or manually updating secrets. New team members can be onboarded faster because access can be granted through proper permissions instead of sharing sensitive values manually. Infisical has improved collaboration between development and operations teams by providing a consistent workflow for managing secrets across local development, staging, production, and CI/CD deployments. Overall, it reduces the risk of accidental secret exposure while making deployments more reliable and repeatable.

    What needs improvement?

    Infisical is already a strong solution for centralized secret management, but there are a few areas where it could be improved. The user experience could be made even more intuitive, especially for teams that are new to secret management platforms because more guidance steps or secret and environment migration tools would help teams onboard faster. Improving documentation with more real-world examples for different architectures such as AWS Lambda and Kubernetes, .NET applications, and multi-account cloud setups would help teams adapt best practices faster. Overall, the product direction is strong and continued improvements around automation, integration, and enterprise governance features would make it even more valuable.

    One area that could be improved further is automation around the full secret lifecycle. Making secret rotation more seamless with cloud services, databases, and third-party providers would reduce manual setups and improve security.

    For how long have I used the solution?

    I have been using Infisical consistently for the past couple of years in my current company.

    What do I think about the stability of the solution?

    We have not encountered any significant stability issues because it has been pretty stable throughout the development that we have implemented so far. The platform has been stable and reliable for our needs. We have not experienced any significant downtime or reliability issues that have impacted our development or deployment workflows because once they have been loaded, they perform their job well. The platform has performed well for managing secrets across environments and the availability has been pretty consistent and reliable in our experience.

    The main reliability benefit is that it provides a centralized and predictable way to access secrets rather than relying on manually maintained configuration files or shared credentials. It is pretty stable in my opinion because we have not encountered any downtime.

    What do I think about the scalability of the solution?

    Infisical has been able to support our current needs and provides a scalable approach as our applications and environments grow. The ability to organize secrets by project, environment, and access permissions makes it easier to manage increasing complexity without adding significant operational overhead. We can manage multiple projects as well. As our usage grows, areas such as advanced automation, deep integration, and more granular governance capabilities will become increasingly important, but overall, Infisical provides a solid foundation for scaling secret management.

    How are customer service and support?

    We have not encountered any situation where we have needed to cooperate with their customer service support because we have not run into any trouble that we should refer to their customer support. The documentation and available resources have been very useful for resolving common issues independently. When dealing with more advanced scenarios, having access to knowledgeable support helps reduce the time needed to troubleshoot those issues.

    Which solution did I use previously and why did I switch?

    Previously, we used other solutions, but as the number of applications and environments grew, managing secrets consistently became more challenging. This is the main reason we moved to Infisical to have a centralized solution with better access control, auditing, versioning, and developer workflow. It simplified secret management across development, staging, and production while reducing the risk of secrets being stored or shared incorrectly.

    How was the initial setup?

    Pricing and the licensing model were straightforward and easy to understand. The setup cost was relatively low because Infisical does not require significant infrastructure changes. We were able to integrate it into our existing workflows without major overhead. The main value comes from reducing the operational effort around managing secrets, improving security practices, and making deployments more consistent. The licensing model provides flexibility as teams and usage grow, although continued improvements around enterprise-level cost visibility and usage insights would make planning even easier.

    What about the implementation team?

    We use AWS as our primary cloud provider because Infisical fits well into our AWS-based workflows by helping us securely manage application secrets and environmental configurations across all our environments.

    We did not purchase Infisical through the AWS Marketplace. We use Infisical as a separate service and integrate it with our AWS workloads through our existing development and deployment workflows. We have a separate team to manage them. We use Infisical as a separate service and integrated it with our AWS workloads.

    What was our ROI?

    We have seen a positive return on investment, mainly through improved productivity, reduced operational overhead, and stronger practices. We have not measured a direct cost saving in terms of reduced headcount, but the main benefit has been time savings and reduced manual effort. The best benefit is that we do not have to share our .env files throughout the team. Developers spend less time requesting, sharing, and troubleshooting environment secrets because everything is centrally managed with controlled access. Setting up new environments and onboarding new team members is also faster because the required secrets and permissions are already structured well.

    What's my experience with pricing, setup cost, and licensing?

    We have a separate team that manages the resources with the outcome. Pricing and the licensing model were straightforward and easy to understand. The setup cost was relatively low because Infisical does not require significant infrastructure changes. We were able to integrate it into our existing workflows without major overhead. The main value comes from reducing the operational effort around managing secrets, improving security practices, and making deployments more consistent.

    Which other solutions did I evaluate?

    We use Infisical through a public cloud deployment model because it allows us to leverage a managed service while benefiting from scalability, availability, and reduced operational overhead. It integrates well with our cloud-based development and deployment workflows, allowing teams to securely manage secrets across different environments without maintaining additional infrastructure.

    In the initial stages, we evaluated a couple of alternatives before choosing Infisical. We looked at options such as AWS Secrets Manager since we rely most on AWS, and HashiCorp Vault and other cloud-based secret management solutions. The main considerations were security, ease of integration, developer experience, operational overhead, and how well the solution would fit into our existing AWS and CI/CD workflows.

    What other advice do I have?

    Infisical is a great tool if you are looking for a tool to manage secrets because the amount of features that Infisical provides and the amount of reliability and shareable resources make it a source of truth and make it easy for teammates to manage secrets. It is very easy to use and it is a lifesaver when you are working in the software development lifecycle.

    I think anyone who is asking whether to shift to Infisical would find that it is the best option if they are looking for something to manage secrets. Infisical is a great tool to manage all your secrets and rather than just a tool, I think it is a lifesaver that people can use to make their software development much easier, especially when they are using it with the proper team. Wherever I go, whenever I need to manage my secrets, I would definitely go with Infisical. I would rate this product a nine out of ten.

    Accounting

    Great State of the Art solution

    Reviewed on Jul 09, 2026
    Review provided by G2
    What do you like best about the product?
    State of the Art Deployment and upgrade process. Clean UI. Developer focused integrations
    What do you dislike about the product?
    Occasional smaller bugs, but responses are rapid and corrective actions are transparent.
    What problems is the product solving and how is that benefiting you?
    We needed a state of the Art replacement of our former Secret management Solution and found it with Infisical.
    Financial Services

    Infisical Streamlines Secret Management with Sync, Kubernetes Delivery, and Audit History

    Reviewed on Jul 08, 2026
    Review provided by G2
    What do you like best about the product?
    I like Infisical because it combines managed secret synchronization, a Kubernetes operator for seamless secret delivery, comprehensive audit history for compliance and visibility, and automatic secret rotation to reduce operational overhead while improving security.
    What do you dislike about the product?
    It doesn’t have the features I need yet.
    What problems is the product solving and how is that benefiting you?
    It helps us handle secret rotation, RBAC for both teams and individual users who need access to secrets, compliance requirements around secrets, and local use of secrets during development.
    Government Administration

    Infisical: Quick Setup, Intuitive Secrets & Certificate Management, and Excellent Support

    Reviewed on Jul 06, 2026
    Review provided by G2
    What do you like best about the product?
    From the very first stages of evaluating a secrets management platform, Infisical made a strong impression. During the initial research phase, we received quick and clear answers to our questions, making it easy to get a solid understanding of the platform's capabilities and whether it would fit our organization's needs.

    When requesting a price quote for the enterprise version, our interaction with GTM/sales was smooth and professional. They took the time to understand our specific situation without resorting to typical sales pitches — just clear, straightforward communication.

    The technical side is equally convincing. Setting up secrets management turned out to be surprisingly quick and easy, even in a somewhat more complex environment. The same goes for certificate management: intuitively designed and free of unnecessary complexity, allowing us to become operational fast.

    In short: a platform that's not only technically solid, but where the people behind the product make a real difference too. A pleasant experience from start to finish.
    What do you dislike about the product?
    So far, nothing significant to report. The onboarding, secrets management setup, and certificate management have all gone smoothly, and the sales/support experience has been positive throughout.
    What problems is the product solving and how is that benefiting you?
    Until now, we haven't experienced any problems.
    Dennis U.

    Intuitive, Fast, and Well-Supported. Infisical Makes Implementation Easy

    Reviewed on Jul 06, 2026
    Review provided by G2
    What do you like best about the product?
    We're still implementing Infisical for using within our new multi-hybrid platform. What we notice so far is that Infisical has a very inuitive interface and is easy to use. It is well documented and we got very patient support on our implementation. We are implementing Infisical for its broad integrations. I noticed walking throught the interfaces that it's performing fast. Though I am not from accounting I do not know the pricing, but I can tell you get a lot in one product and very helpfull support. So it may be worth the price!
    At this moment we have not checked the AI functions, but we expect it to be helpfull in our token life cycle management using the Infisical Agent. We will also explore all other AI support for our Kubernetes platform. And use it to get the full product experience.
    What do you dislike about the product?
    We've not discovered any downsides of the program.
    What problems is the product solving and how is that benefiting you?
    A single point for secrets and certificates management, which fully integrates in our complete platform, serving multiple municipalities.
    Haim S.

    Solid Secret Management with Smooth K8S Integration and Great Support

    Reviewed on Jul 03, 2026
    Review provided by G2
    What do you like best about the product?
    Solid secret management solution.
    K8S integration works well and we didn't experienced any performance issues yet.
    UI is very informative.
    Great support - Quick response on questions, issues and suggestions
    What do you dislike about the product?
    Some areas are not fully "baked" yet (Helm charts, some K8S features, etc), so workarounds might be required.
    UI changes from time to time so need to get use to.
    What problems is the product solving and how is that benefiting you?
    Unifying secret management across all our company teams.
    Fully managed and supported solution.
    reviewer2865399

    Secure role-based secret storage has protected our tools and simplifies day-to-day access

    Reviewed on Jun 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Infisical is to store secrets for other programs and tools, and I use it for that most often. For example, we had access keys for the local GitLab instance and those were stored inside Infisical and fetched from there. That is mostly what Infisical was used for with other tools as well.

    What is most valuable?

    In my opinion, the best features Infisical offers are the security aspects, as the security made it difficult to access all the secrets very easily. When I refer to security features, the overall sense of security is mostly what I liked, but I would say the role-based access was very nice.

    Infisical has positively impacted my organization, and even though I was an intern, I noticed improvements or benefits after using it as that was part of the assignment.

    What needs improvement?

    I believe Infisical can be improved by adding more features. I don't think there is a specific feature missing or something I had in mind for improvement; I believe continuing on the current path and expanding what has already been done is the best course of action for Infisical.

    For how long have I used the solution?

    I have been using Infisical for about five months.

    What do I think about the stability of the solution?

    I haven't experienced any issues or downtime with Infisical.

    What do I think about the scalability of the solution?

    I didn't notice any challenges or strengths regarding Infisical's scalability as that wasn't my responsibility.

    How are customer service and support?

    I have no knowledge about the customer support for Infisical because I didn't have to reach out to them.

    Which solution did I use previously and why did I switch?

    I haven't used a different solution for secret management before, so I have no basis for comparison.

    What other advice do I have?

    I would advise others looking into using Infisical to really examine the documentation they provide because it is very useful. Infisical is a nice, modern tool in secret management. I gave this review a rating of 8.

    Tarcisio Rocha

    Centralized secrets have secured CI/CD pipelines and prevent password traces in terminals

    Reviewed on Jun 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Infisical is to store my CI/CD secret keys, which I use in GitHub.

    A quick and specific example of how this integration makes my work easier is that it adds a lot of security in the sense of not using passwords in command prompts. That way, I can send commands directly in GitHub using Infisical's secret passwords, without having to leave traces in the commands directly in the terminal.

    Regarding how Infisical contributes to security or to the management of passwords and commands in my routine, it prevents us from leaving passwords in the command prompts. Alongside GitHub, GitHub does not store passwords. Instead, it accesses Infisical directly through the application without leaving command traces in any prompt. It is excellent regarding security in command prompts, with no password traces.

    What is most valuable?

    Infisical's best features include the ease I have to store passwords and manage the users who will use those passwords. That helps a lot.

    User management through Infisical makes my work easier because I am able to manage the access levels to the types of passwords that I have stored in Infisical. This allows me to have higher access levels with higher-level passwords and deeper levels of access.

    Infisical is extremely simple to use, so it is important to emphasize how easy it is to handle the platform as a whole. It is very straightforward and very easy to deal with in terms of how it is laid out.

    Infisical has had a positive impact on my organization mainly in the level of security regarding the use of passwords that give direct access to the server. We stopped using passwords directly on personal computers. This ensures a very high level of security for both those in development and those in management. There are possibilities of computers breaking or losing saved passwords. If someone breaks into my personal computer, that person will not have access via prompt to my high-level passwords. This security segregation raises and gives much more credibility to the company as a whole.

    I have noticed time savings in access management after adopting Infisical as the main benefit. Regarding leaks, we have not had anything proven related to leaks yet.

    What needs improvement?

    I have not encountered any limitation in Infisical. I use the free version and have not had any limitations. It is excellent. In the way we are using it as a test, it will certainly be used as an indispensable tool in any CI/CD operation in GitHub and servers.

    Infisical already fully meets my needs at the moment.

    For how long have I used the solution?

    I have been using Infisical for a year.

    What do I think about the stability of the solution?

    Infisical is stable, as I never experienced any instability. I never had any problems with it.

    What do I think about the scalability of the solution?

    Infisical's scalability works well when there is an increase in the volume of users or data. With the increase in the number of users, I did not feel any difference because the CI/CD I use is for a small company. The number of developers using the CI/CD platform, where Infisical is embedded, is not stressed enough.

    How are customer service and support?

    I have not needed to contact Infisical's customer support because, as I mentioned, it is highly resilient and sustainable regarding its configurations.

    Which solution did I use previously and why did I switch?

    I previously tried to use a different solution before Infisical, but it was extremely complex and did not work out. I do not remember the name, but it is one of the best on the market as well. I found it extremely complex. I decided to migrate to Infisical because I saw some friends saying it was good.

    How was the initial setup?

    My experience with Infisical's pricing, setup costs, and licensing is excellent. Even using the free version, it fits perfectly for small solutions for small companies. It is very worthwhile.

    What was our ROI?

    I have obtained a return on investment using Infisical, with a reduction in time of up to 15 minutes when using manual passwords. We stopped using manual passwords and started using Infisical's application layer. This reduced those 15 minutes of waiting time to practically instantaneous. We no longer have to wait for the terminal to finish the process so we can focus on other things.

    What's my experience with pricing, setup cost, and licensing?

    My experience with Infisical's pricing, setup costs, and licensing is excellent. Even using the free version, it fits perfectly for small solutions for small companies. It is very worthwhile.

    Which other solutions did I evaluate?

    Before choosing Infisical, I evaluated other options, specifically HashiCorp. With this company, I had extreme difficulty configuring the panel, and I found Infisical very intuitive.

    What other advice do I have?

    The advice I would give to others considering using Infisical is to test it, because these other tools that exist, such as HashiCorp, are extremely expensive and extremely complex. Infisical brings exactly this ease for the end user to be able to do a good job with quality and at an extremely affordable price. I would rate my overall experience with Infisical a 10 out of 10.

    Raja Prasad

    Secure secret sharing has streamlined environment management for multiple cloud applications

    Reviewed on Jun 20, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I primarily use Infisical for keeping the environment values that are used in our applications. We also use Infisical for secret sharing with our developers and clients using Infisical's secret sharing feature. We integrate Infisical to use environment values in our Dockerfile.

    What is most valuable?

    We use self-hosted Infisical in our AWS ECS cluster as a Docker container, primarily for secret sharing and keeping secrets in a very secure manner. We can give Infisical access to our developers so they can update and delete secrets when required for our dev and staging environments. For the production environment, we keep our environment values in Secrets Manager instead.

    Infisical has improved security significantly. It helps developers to update environment variables in Infisical because as members of Infisical, they can login as users. All developers have access to Infisical, making it very easy for them to update, delete, and restore environment variables or secrets. Infisical's secret sharing feature is the best feature where we can set time limits for how many times and for how long a developer or any other entity can access that link to get the environment variables.

    It saves considerable time because updating environment variables to other platforms like AWS or other secrets managers requires logging in and then updating the secrets, which takes more time. Storing environment variables in Infisical is very easy, and since we have self-hosted Infisical, all data and everything resides on our premises only. We plan to continue using Infisical long term because it is more secure than Infisical cloud.

    What needs improvement?

    When I use Infisical CLI tool, which is created via Go language as a Go binary, sometimes the Go binary is not updated. When we scan Infisical using the Trivy vulnerability scanning tool, we found issues with Infisical CLI Go binaries that are not updated with the latest version. Due to that, Trivy vulnerability scanning fails. Our solution is to bypass the Go binary during Infisical vulnerability scanning steps. I suggest that the Infisical team update the Go binaries in their Infisical CLI.

    For how long have I used the solution?

    I have been using Infisical for the last two years with a self-hosted Infisical instance in our AWS cloud.

    Which solution did I use previously and why did I switch?

    We previously used AWS S3 bucket to keep our environment variables. We switched because storing environment variables in S3 bucket was very time-consuming. Whenever we needed to update an environment variable, we had to download the environment files, change them, and then upload them back to the S3 bucket, which was very time-consuming and hectic.

    What's my experience with pricing, setup cost, and licensing?

    The setup cost was very minimal for us at around twenty dollars.

    What other advice do I have?

    I suggest every organization to use Infisical unless you are using Trivy for vulnerability scanning, otherwise your pipeline will be blocked. I strongly suggest Infisical to update their Go binaries in their Infisical CLI tool. I give this product a rating of eight out of ten.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)