Transparent file-level encryptionYour secrets, encrypted at rest.
Your secrets, encrypted at rest.
Invisible to your workflow.
Mark .env, kubeconfigs, cloud credentials, and SSH keys as protected. Toast keeps them encrypted on disk and decrypts on read for the tools you trust — without changing how you build.
Demo preview · no real encryption performed
live
5
Protected files
live
1284
Access events / 24h
live
7
Keys rotated this wk
live
1
Policy violations
Protected files
Encrypted at rest · decrypted in-memory for trusted processes
File
Algorithm
Size
Last access
- .env.production~/projects/orbital-api/EncryptedAES-256-GCM4.2 KB2 min ago
- ~/.kube/config/Users/dana/.kube/EncryptedAES-256-GCM12.1 KB14 min ago
- aws_credentials~/.aws/EncryptedChaCha20-Poly13051.8 KB1 hr ago
- id_rsa~/.ssh/EncryptedAES-256-GCM3.4 KB3 hr ago
- gcp-service-account.json~/secrets/Rotating keyAES-256-GCM2.6 KByesterday
- .env.local~/projects/landing/Action neededUnprotected1.1 KB5 min ago
Showing 6 of 6 protected files
Recent access
Live audit trail · last 24 hours
Connected vaults
Source of truth for master keys
1Password
Personal · Engineering
HashiCorp Vault
acme-eng / kv-v2
AWS Secrets Manager
us-east-1 · prod
Bitwarden
Personal
CLI & IDE integration
Drop-in for the tools you already use
~/projects/orbital-api
$ toast protect .env.production→ wrapping key from 1Password (vault: Engineering)✓ encrypted .env.production (AES-256-GCM)$ toast status5 protected · 0 leaked · 1 need review$ toast run -- node server.js→ decrypted in-memory for PID 1290 (node)✓ process exited cleanly
VS CodeJetBrainsNeovimiTermWarpGitHub Actions
Team policy
acme-eng · 14 developers
Require encryption for .env*
Enforced across 12 repos
Block plaintext kubeconfigs
Auto-encrypt on detect
Rotate cloud credentials
Every 30 days · last: 6d ago
Allow personal vault override
Disabled by security
1 file needs review
.env.local don't match team policy.
Daemon healthy 0.4% CPU · 18 MB RAM Touch ID unlocked · 3h 42mbuild c4a91e2
Interactive demo concept · presented inside The Eureka Database