The fastest secrets management for dev teams to ship securely. Creators of securelog.com

Joined November 2020
140 Photos and videos
Onboardbase retweeted
27 Mar 2025
I can't believe Emily is managing secrets with a sheet of paper. Jack had to type it all in to start the project on his first day šŸ˜‚šŸ¤¦šŸ½
2
2
280
Onboardbase retweeted
19 Mar 2025
One of the most essential things vibe coders need is a Store or Vault. A secure and efficient way to store and retrieve secrets. A straightforward API providing an encrypted key-value store for your customers’ secrets. Use Cases 1ļøāƒ£ API keys - Secure your customer API keys. 2ļøāƒ£ JWT tokens - Store your JSON Web Tokens and refresh tokens securely. 3ļøāƒ£ License keys - Protect your customer license keys for product activation. 4ļøāƒ£ Domain names - Need to build a custom domain feature? Store them securely. 5ļøāƒ£Passwords - Store your salted passwords securely. @onboardbase we launched Store a while ago. onboardbase.com/blog/store @WorkOS launched Vault yesterday x.com/grinich/status/1902020… @unkeydev has a Vault as well engineering.unkey.com/archit… Take your pick, but no excuses for not balancing security with speed as you vibe code to success.

WorkOS Launch Week - Day 2 šŸ” WorkOS Vault šŸ” Vault is a brand new service to secure enterprise customer data, inspired by what companies like Slack, Airtable, and Box have built. So how does it work and why does your app need it? šŸ‘‡
2
7
514
Onboardbase retweeted
13 Mar 2025
So Cursor uploads .env file with secrets despite .gitignore and .cursorignore. This is one of the biggest concerns I've seen with Cursor. I'm not sure using Cursor with repositories with secrets or personal information is safe. It's easy to fix this by using something like onboardbase.com. It removes the .env files from your project, so it's no longer a concern. Join the discussion here. news.ycombinator.com/item?id…

1
2
373
Onboardbase retweeted
11 Mar 2025
Vibe Code all you want. Onboardbase Securelog keep it safe. 30 mins to bulletproof your SaaS. Go to onboardbase.com & securelog.com—then show us your app. Million Kids, Million Wins. šŸš€ 8/8
2
2
324
Onboardbase retweeted
11 Mar 2025
A million vibes, a million shots. Don’t let yours crash. Try this, build that wild idea, and flex it. What’s your project? Drop it below—let’s hype it up! 7/8
1
2
2
251
Onboardbase retweeted
11 Mar 2025
Real talk: Let's zoom out for a bit. Zoom got roasted for weak security, fixed it, and won. You can, too—without the drama. onboardbase.com securelog.com = free trials, no excuses. Protect your summer hit now. 6/8

1
2
2
229
Onboardbase retweeted
11 Mar 2025
How to lock it down: 1ļøāƒ£ Deploy to Vercel (you’re already a pro) 2ļøāƒ£ Onboardbase for keys (10 mins) 3ļøāƒ£ Securelog for sanitization (10 mins) 30 mins total—back to vibing, but untouchable. 5/8
1
2
2
236
Onboardbase retweeted
11 Mar 2025
@secureloghq = your growth bouncer. 1ļøāƒ£ Drop the SDK in NextJS 2ļøāƒ£ Spot and sanitize sketchy logins, secrets, agents, conversations 3ļøāƒ£ Scale from 50 to 5k users It’s your audit vibe—keeps the app tight when it blows up. 4/8
1
2
3
282
Onboardbase retweeted
11 Mar 2025
@onboardbase = your key management wingman. 1ļøāƒ£ npm i -g @onboardbase/cli 2ļøāƒ£ onboardbase setup 3ļøāƒ£ Pull keys, done. 5 mins, Multilayer encrypted, Vercel-ready. Keep coding, stay safe. 3/8
1
2
4
298
Onboardbase retweeted
11 Mar 2025
Why care? Your app’s a banger—meme generator, chat tool, flight simulator, boat cruise, whatever. But unprotected Supabase/Stripe keys = hacked in 5 mins. Trust gone, vibes dead. Security’s not a buzzkill—it’s your shield. 2/8
1
2
2
330
Onboardbase retweeted
11 Mar 2025
A million kids are building a million SaaS ideas with v0,bolt,cursor,replit,etc. Vibe coding in the purest sense. But here’s the tea: your weekend project’s a sitting duck without security Don’t kill the vibe—save it with Onboardbase & Securelog. Let’s break it down. šŸ§µšŸ‘‡ 1/8
2
5
12
2,535
Onboardbase retweeted
8 Mar 2025
Envkit - Auth or SSO for Env is coming along nicely. Here are some of the things to expect from it. āœ… EnvKit—An <Env/> component to replace your default project/repo start page. āœ… Missing envs—If you don't know the required envs, you will see this page, where you can add them or connect with an env provider. āœ… Dev Only—Dev-only component and stays in git so others would know which env values to even ask for. No more creating env.txt files with dummy values. āœ… Other possible use case—Allow apps to easily collect user's env variables, with the ability to connect to Onboardbase or a secret manager of choice (which stores the env variables)
3
2
6
768
Onboardbase retweeted
26 Feb 2025
I have been thinking about this a lot. šŸ˜… An <env /> component to replace your default project start page. āœ… If you don't know the required envs, you see this page where you can put the env or connect with an env provider. āœ… Customize the page's look, no more default starter page of the framework.
1
3
4
519
Onboardbase retweeted
23 Feb 2025
✨ Securelog is very good for AI agents. It's a plug-and-play "security brain" that agents can call upon. It can handle everything from sanitizing training data to securing runtime interactions. Apply or create "Custom Rules," and it works; no code changes are needed.
2
3
245
Onboardbase retweeted
12 Feb 2025
Terraform stands out as one of the most reliable Infrastructure as Code (IaC) tools to provision and manage cloud resources: just write a few lines in a Terraform configuration file and spin up cloud services in minutes in any cloud provider. But this ease of use also brings security challenges: a leak of your Terraform state files could reveal sensitive information, bring your infrastructure down, and ultimately hurt your reputation as a company. All it takes is an overworked colleague and a single bad `git commit`. Let me tell you how to protect your Terraform state files at rest and in transit using Onboardbase’s command line interface tool in five minutes without compromising the developer experience for your entire devops team. But why should I download another tool, Dante?? you might ask. I already use Hashicorp Vault. As I’ll explain in a minute, Hashicorp Vault only solves a part of the problem. @onboardbase is a 360° solution that goes beyond the devops team to integrate requirements from your entire IT department. Just read on, and you’ll understand right away. Read the full article here onboardbase.com/blog/terrafo…

1
1
140
Onboardbase retweeted
9 Feb 2025
1
1
204
Onboardbase retweeted
9 Feb 2025
šŸ”„ Custom Rules on Securelog. Rules can be anything from SSN, Credit Card, Phone number, DNA sequence, and API Token. Basically, anything you consider a secret. You can parse this directly into Securelog, and it will redact it quickly. ā˜ŗļø Link to try it out below šŸ‘‡šŸ½
1
2
2
498
Onboardbase retweeted
TIL onboardbase.com/. dope.

4
2
12
1,959
Onboardbase retweeted
5 Dec 2024
I think onboardbase.com works well here—especially the yaml file. You can add your secrets but still be able to override them for local use cases specific to you.
4 Dec 2024
Are you sticking API endpoints in environmental variables? Or flipping them in config like this?
2
2
582
Onboardbase retweeted
5 Dec 2024
even with the cold, still a fun turnout for devtools toronto #2 we had toolsmiths & hackers last night from @Stellate @github @Tempo_Labs @onboardbase @ShopifyEng @vltpkg @SST_dev @getsentry @wearedmno @noti_api and more šŸ™ big thanks to our sponsors @rootlyhq and @getsentry
21 Nov 2024
šŸ‡ØšŸ‡¦ Due to popular demand, DevTools Toronto is returning on Wednesday, Dec 4th! Now with an even more impressive slate of VIP guests. RSVP here: guild.host/events/devtools-t…
2
3
24
3,118