01Performs cryptographic operations (sign, encrypt, decrypt) without exposing private key material
02Supports various vault backends including OpenBao, HashiCorp Vault, and cloud KMS providers
03Maintains a full, tamper-evident audit trail for every operation with multiple logging sinks
04Vends short-lived LLM API keys and generic secrets over mTLS, with zero secrets on disk
05Enforces a deny-by-default policy engine with granular access controls based on team, scope, and operation
060 GitHub stars