What the buyer is really asking
Buyers ask this to make sure passwords, API keys, and certificates are not sitting in source code or a shared doc. Name the system that stores your secrets and explain who can get into it.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you manage secrets and credentials?”
- “Are secrets stored in source code?”
- “What tool do you use for secrets management?”
- “How are certificates managed and renewed?”
Evidence to have ready
- The secrets manager in use and its access policy
- Secret scanning configuration on your repositories
- Certificate management or auto-renewal settings
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.