How ServerSecretVault handles your secrets

ssv runs on servers full of credentials, so it is built to touch as little as possible. This page sets out what it reads and writes, what it never does, how to check the copy you download, and how to report a security issue.

What ssv reads and writes

  • ssv scan and ssv audit read each file's owner, permissions, size and modification time, and read its contents only to compute a SHA-256 checksum. Reports show paths, metadata and checksums, never secret values.
  • ssv backup reads the files it found and streams them straight into age. The only file it writes is the encrypted backup, which is readable by its owner only (mode 0600). An unencrypted copy of the archive is never written to disk.
  • ssv creates no configuration files, services or caches.

Security model and limitations

  • ssv helps you avoid inventory and backup mistakes; it can't guarantee that every secret on a server is found.
  • Run it as root only when you need to see other accounts' files.
  • ssv never prints secret values, never makes network requests, and never changes, moves or deletes files, permissions or credentials.
  • Severity depends on how isolated the server's accounts are. On a single-site server 0644 may be fine; on a shared server it lets every account read the file. That's why world-readable files are marked REVIEW rather than an error.
  • ssv opens files without following symbolic links and refuses anything that isn't a regular file, so other users on the server can't trick it into reading or backing up files outside their own.
  • Owner and group names come from /etc/passwd and /etc/group. Accounts that come from LDAP or SSSD appear as numeric IDs.

Backups you can restore without ssv

Backups are age-encrypted tar archives. Restoring one needs only age and tar, so your backups stay readable even without ssv. With key-based backups, the key needed to decrypt them never has to be on the server. See restoring from a backup.

Verifying a download

The installer:

  • downloads over HTTPS from serversecretvault.com,
  • checks the package against its SHA-256 checksum in SHA256SUMS and stops if it doesn't match, so nothing is installed,
  • installs ssv under a temporary name and renames it into place, so an ssv that is running at that moment is never modified.

To read the installer before running it:

curl -fsSLO https://serversecretvault.com/install.sh
less install.sh
sudo sh install.sh

To verify a package by hand, download it with SHA256SUMS and run sha256sum -c --ignore-missing SHA256SUMS. The install guide has the full steps.

Reporting a vulnerability

If you find a security issue in ssv or in this website, email info@serversecretvault.com or use the contact form with the topic "Security report". Please include:

  • the ssv version (ssv version) and your Linux distribution,
  • what you found and how to reproduce it,
  • the impact you expect.

Never send real passwords, API keys or the contents of a .env file; describe them instead. This contact information is also published in security.txt.

This website

  • No cookies. Visits are counted with Ahrefs Web Analytics, which does not use cookies.
  • A Content Security Policy allows scripts only from serversecretvault.com and analytics.ahrefs.com.
  • Fonts are loaded from Google Fonts.
  • Messages sent through the contact form are stored on this server and forwarded to our inbox by email.

Last updated 2026-10-08 · for ssv 0.2.0