Hacker News new | ask | show | jobs
by vmatsiiako 1281 days ago
This is totally valid! And that's why we decided that Infisical should be open-source. As you said, you can inspect everything yourself, and even self-host it, for even greater level of certainty. Infisical is by default end-to-end encrypted with exceptions for a couple integrations (Vercel/Heroku). This is because it is impossible to preserve end-to-end encryption there at the moment - this will be possible with custom integrations in future. We try to be very open about this with users (we mention it both in the app and in the docs multiple times).

Certifications are definitely important, and we're actively thinking of that.