Securing Secrets from Dev Machine to Deployments Using SLV

By Shibly Meeran , Sriram Krishnan , Keshav Kandasamy on 10 Dec 2025 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
#devsecops #cicd-security #supply-chain
Focus Areas: πŸ“¦ Software Supply Chain Security , πŸ” Application Security , βš™οΈ DevSecOps
This tool demo covers following tools where the speaker has contributed or authored
SECURE-LOCAL-VAULT

Abstract

SLV (Secure Local Vault) bridges the gap between local developer environments and secure CI/CD pipelines by offering a lightweight, CLI-first tool for managing secrets without relying on centralized, cloud-hosted secrets managers. The talk demonstrates how sensitive credentials can leak across development to production workflows and how SLV prevents this through isolated, encrypted vaults, ephemeral secrets injection, and audit-friendly flows. With real-world attack paths as context, the demo shows how SLV hardens secrets handling from the first line of code to final deployment.

Presented at Black Hat Europe 2025 Arsenal, December 8-11, London. Track: Cloud Security.