Vendor Observatory

Revealed Preference

Benchmarks
Vendor IntelPrompt Intel
Analytics
QuerySearchInsights
Data
VendorsPlatformsActionsSessions
v0.2.0
Home/Secrets Management
🔑

Secrets Management

Secret rotation, env var management, vaults

Each prompt simulates a real developer scenario asking AI coding assistants to recommend a secrets management vendor. Below: which vendors were recommended, how well they addressed constraints, and the reasoning behind each recommendation.

Top Vendor

doppler

6 of 12 recommendations

Responses

30

across 3 prompts

Constraint Coverage

32%

14 constraints tracked

Platforms Tested

claude_codecodex_cli

Vendor Leaderboard

#VendorRecommendationsShare
1doppler6
50%
2hashicorp-vault2
17%
3aws-secrets-manager2
17%
4infisical1
8%
5github-actions1
8%

Prompt Breakdown

Centralized Secrets Replacing Scattered .env Files

Secrets in Slack DMs and Google Docs, .env accidentally committed to Git, 12 API keys rotated

sec-01
10 responses
Top: doppler
Pain point: secrets in Slack DMs and Google Docs, .env committed to Git
Stack:dotenv filesgithub actionsrailwayvercel
Asked about:dopplerinfisical1passwordhashicorp-vault
Existing StackCompliance/SecurityFramework-SpecificStarts from PainConstraint-LedExisting Vendor
✗ no self hosted✓ github actions integration✗ railway vercel integration✓ access control✓ audit log
claude_codeImplementeddoppler
claude_codeImplementeddoppler
claude_codeRecommendedNo primary vendor identified
claude_codeRecommendedNo primary vendor identified
claude_codeImplementedhashicorp-vault

Doppler Wins for Your Use Case

claude_codeImplementedNo primary vendor identified

Doppler Wins for Your Use Case

claude_codeImplementedNo primary vendor identified

Doppler Wins for Your Use Case

claude_codeImplementedhashicorp-vault

Doppler Wins for Your Use Case

codex_cliImplementedgithub-actions
codex_cliImplementeddoppler

Zero-Touch Secret Sync Across Dev/CI/Production

Wiki page always out of date, manually updating GH Actions secrets, staging/prod confusion

sec-02
10 responses
Top: doppler
Pain point: wiki page always out of date, manual GH Actions secret updates, staging/prod confusion
Stack:dotenv filesgithub actions secretsvercel
Asked about:dopplerinfisicalvercelaws-secrets-manager
Existing StackFramework-SpecificWorkload DefinedStarts from PainConstraint-LedExisting Vendor
✗ managed hosted✓ env hierarchy✓ vercel preview integration✓ zero manual ci
claude_codeImplementedNo primary vendor identified

Not the Others?

Gotchas: Vercel integration requires custom setup - ✅ Secret rotation support - ✅ Free tier: unlimited users, but limited features - **Best for**: Teams wanting open-source with self-host option later

claude_codeImplementedNo primary vendor identified

Not the Others?

Gotchas: Vercel integration requires custom setup - ✅ Secret rotation support - ✅ Free tier: unlimited users, but limited features - **Best for**: Teams wanting open-source with self-host option later

claude_codeRecommendedNo primary vendor identified
claude_codeRecommendedNo primary vendor identified
claude_codeImplementedNo primary vendor identified

Doppler Wins for Your Use Case

claude_codeImplementedNo primary vendor identified

not the others:** - **Vercel Env Vars:** No CLI injection (writes files), 4KB limit per deployment, no cross-platform hierarchy (useless for GitHub Actions without manual copying)

claude_codeImplementedNo primary vendor identified

Doppler Wins for Your Use Case

claude_codeImplementedNo primary vendor identified

not the others:** - **Vercel Env Vars:** No CLI injection (writes files), 4KB limit per deployment, no cross-platform hierarchy (useless for GitHub Actions without manual copying)

codex_cliImplementeddoppler
codex_cliImplementedinfisical

SOC 2 Secrets Management with Automated Rotation

Auditor flagged: no rotation (keys 2+ years old), no audit trail, shared service accounts

sec-03
10 responses
Top: doppler
Pain point: SOC 2 audit findings — no rotation, no audit trail, shared credentials
Stack:github actionsaws ecsnodejs
Asked about:hashicorp-vaultdopplerinfisicalaws-secrets-manager
Existing StackCompliance/SecurityFramework-SpecificWorkload DefinedStarts from PainConstraint-LedExisting Vendor
✗ soc2 type ii✗ automated rotation 90d✓ audit logging✗ fine grained acl✓ encryption at rest
claude_codeRecommendedNo primary vendor identified
claude_codeRecommendedNo primary vendor identified
claude_codeRecommendedNo primary vendor identified
claude_codeRecommendedNo primary vendor identified
claude_codeImplementeddoppler

Doppler Enterprise Wins for This Use Case

claude_codeImplementedaws-secrets-manager

Not the Others?

claude_codeImplementedaws-secrets-manager

Not the Others?

claude_codeImplementeddoppler

Doppler Enterprise Wins for This Use Case

codex_cliRecommendedNo primary vendor identified

this recommendation wins for SOC 2

codex_cliRecommendedNo primary vendor identified

Constraint Coverage

github actions integration8/1080%
access control8/1080%
audit log8/1080%
audit logging6/1060%
encryption at rest6/1060%
vercel preview integration4/1040%
zero manual ci3/1030%
env hierarchy2/1020%
no self hosted0/100%
railway vercel integration0/100%
managed hosted0/100%
soc2 type ii0/100%
automated rotation 90d0/100%
fine grained acl0/100%