Skip to content

CyberLegion Secryn ​

Secrets Management solution on CyberLegion — Secrets Management

CyberLegion Secryn is the Secrets Management product for inventory, posture, leakage response, rotation, agent secrets, and vault governance.

Start with Secryn

Use your tenant account to open it, sign in, or request access. API calls use the same governed execution endpoint as the console.

API endpoint
POST https://api.dev.cyberlegion.io/execute
Authorization: Bearer <YOUR_TENANT_API_TOKEN>
Content-Type: application/json

{
  "app": "<app id from this solution>",
  "input": {}
}

Apps In This Solution ​

CyberLegion Secryn groups 11 apps. Each app is a packaged capability your team uses through the console, in chat, or from the public API. Availability follows your tenant plan, roles, and permissions.

AppAreaWhat it does
AgentVault—Scoped secrets for AI agents, tools, MCP connections, and delegated work.
CloudVault—Cloud secret managers, workload identity, KMS links, and cross-account posture.
LeakWatch—Leak detection, triage, revocation, replacement, and evidence capture.
PipelineGuard—CI/CD secret scanning, masking, policy checks, and build-gate enforcement.
Recovery—Compromise recovery, key ceremony support, break-glass, and service restoration.
Rotate—Rotation policy, orchestration, expiry tracking, and rollback-safe secret replacement.
SecretBroker—Just-in-time brokering, short-lived credentials, and least-privilege grants.
SecretPolicy—Secret classification, policy, approval, exception, and lifecycle governance.
SecretProof—Tamper-evident custody, lineage, proof, and compliance evidence for secrets.
Vault—Vault — approved roadmap app (freeze catalog v1.0, 2026-07-17).
VaultMap—Secrets inventory across vaults, repos, CI, cloud, endpoints, and agent runtimes.

How To Use It ​

ChannelBest for
ChatAsk for what you need in the CyberLegion console; the app plans, executes, and streams results back into your workspace history.
ConsoleOpen any app in this solution from the console, with your tenant's data, roles, and permissions applied.
APIAutomate an app from your own systems through the governed execution endpoint shown in the action panel above, using your tenant API token.

Every request is authenticated, authorized, and audited inside your tenant.

Tenant Safety ​

  • Public docs never show tenant records, identifiers, private URLs, credentials, or configuration.
  • Apps render only the data your tenant returns; empty states stay empty.
  • Keep API tokens in your own vault or runtime environment. Never paste them into docs, tickets, or support requests.

Need help?

Use the Support action above, or browse the app catalog.