About EnvSync
We started EnvSync because sharing secrets in Slack messages and copy-pasted.envfiles was the norm on every team we'd worked on — and every one of those teams had a story about a leaked key that shouldn't have gone where it went.
Security first
Every secret is encrypted at rest with AES-256-GCM before it's ever written to disk. No exceptions, no shortcuts.
Built for developers
A CLI with zero runtime dependencies, real audit logs, and a permission model that maps to how teams actually work.
Nothing hidden
If a feature isn't built yet, we say so. We'd rather ship something real later than fake it now.
Where we are today
EnvSync is early — small team, moving fast, building the core product in the open. If you hit something broken or missing, that's useful signal, not a surprise. See the changelog for what's actually shipped so far.