How ServerSecretVault handles your secrets
ssv runs on servers full of credentials, so it is built to touch as little as possible. This page sets out what it reads and writes, what it never does, how to check the copy you download, and how to report a security issue.
What ssv reads and writes
ssv scanandssv auditread each file's owner, permissions, size and modification time, and read its contents only to compute a SHA-256 checksum. Reports show paths, metadata and checksums, never secret values.ssv backupreads the files it found and streams them straight intoage. The only file it writes is the encrypted backup, which is readable by its owner only (mode0600). An unencrypted copy of the archive is never written to disk.ssvcreates no configuration files, services or caches.
Security model and limitations
ssvhelps you avoid inventory and backup mistakes; it can't guarantee that every secret on a server is found.- Run it as root only when you need to see other accounts' files.
ssvnever prints secret values, never makes network requests, and never changes, moves or deletes files, permissions or credentials.- Severity depends on how isolated the server's accounts are. On a single-site server
0644may be fine; on a shared server it lets every account read the file. That's why world-readable files are marked REVIEW rather than an error. ssvopens files without following symbolic links and refuses anything that isn't a regular file, so other users on the server can't trick it into reading or backing up files outside their own.- Owner and group names come from
/etc/passwdand/etc/group. Accounts that come from LDAP or SSSD appear as numeric IDs.
Backups you can restore without ssv
Backups are age-encrypted tar archives. Restoring one needs only age and tar, so your backups stay readable even without ssv. With key-based backups, the key needed to decrypt them never has to be on the server. See restoring from a backup.
Verifying a download
The installer:
- downloads over HTTPS from
serversecretvault.com, - checks the package against its SHA-256 checksum in
SHA256SUMSand stops if it doesn't match, so nothing is installed, - installs
ssvunder a temporary name and renames it into place, so anssvthat is running at that moment is never modified.
To read the installer before running it:
curl -fsSLO https://serversecretvault.com/install.sh
less install.sh
sudo sh install.sh
To verify a package by hand, download it with SHA256SUMS and run sha256sum -c --ignore-missing SHA256SUMS. The install guide has the full steps.
Reporting a vulnerability
If you find a security issue in ssv or in this website, email info@serversecretvault.com or use the contact form with the topic "Security report". Please include:
- the
ssvversion (ssv version) and your Linux distribution, - what you found and how to reproduce it,
- the impact you expect.
Never send real passwords, API keys or the contents of a .env file; describe them instead. This contact information is also published in security.txt.
This website
- No cookies. Visits are counted with Ahrefs Web Analytics, which does not use cookies.
- A Content Security Policy allows scripts only from
serversecretvault.comandanalytics.ahrefs.com. - Fonts are loaded from Google Fonts.
- Messages sent through the contact form are stored on this server and forwarded to our inbox by email.
Last updated 2026-10-08 · for ssv 0.2.0