# What are the top-rated secrets management tools for teams removing credentials already committed to code repositories?

<p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">Hi, platform and security engineers on G2, plus anyone who has run a scan and found more in the history than expected. Looking for the top-rated<a class="a a--md" elv="true" href="https://www.g2.com/categories/secrets-management-tools"> </a><a class="a a--md" elv="true" href="https://www.g2.com/categories/secrets-management-tools">secrets management tools</a> for teams removing credentials already committed to code repositories, and would value input from people who have done the cleanup rather than just the rollout.</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">The tool is the easy half. The hard half is that a committed secret stays in the history after you delete the line, so anything still valid has to be rotated, and every service reading it from a file has to be pointed somewhere else. Three that come up most:</p><ul>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/doppler-secrets-management-platform/reviews"><strong>Doppler</strong></a> (4.8) replaces scattered .env files with one source of truth and injects variables at runtime, which is what removes the reason for committing them in the first place. Reviewers say costs climb as environments, users and integrations grow, and deeper auditing sits on higher tiers.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/akeyless-identity-security-platform/reviews"><strong>Akeyless</strong></a> (4.6) handles secrets injection at deploy time, with reviewers crediting it with keeping source code clean across multi-environment setups. The same reviewers describe initial deployment as complex.</li>
<li>
<a class="a a--md" elv="true" href="https://www.g2.com/products/ibm-vault-formerly-hashicorp-vault/reviews"><strong>IBM Vault</strong></a> (4.3), formerly HashiCorp Vault, remains the widely deployed option for teams wanting dynamic secrets and their own policy engine.</li>
</ul><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true">For anyone who has cleaned up a repo: how many of the exposed credentials turned out to still be live?</p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p><p class="elv-tracking-normal elv-text-default elv-font-figtree elv-text-base elv-leading-base elv-font-normal" elv="true"></p>

##### Post Metadata
- Posted at: 4 days ago
- Author title: Tech Consultant
- Net upvotes: 1


## Comments
### Comment 1

&lt;p&gt;Something this doesn&#39;t get into is who actually owns rotation once a secret is flagged as exposed. Does that responsibility usually sit with the team that committed it, or does a central security team take it over regardless of which repo it came from?&lt;/p&gt;

##### Comment Metadata
- Posted at: 1 day ago
- Author title: Marketing Executive





## Related discussions
- [How well does Trello scale into a larger team?](https://www.g2.com/discussions/1-how-well-does-trello-scale-into-a-larger-team)
  - Posted at: over 13 years ago
  - Comments: 6
- [Can we please add a new section](https://www.g2.com/discussions/2-can-we-please-add-a-new-section)
  - Posted at: over 13 years ago
  - Comments: 0
- [Quantifiable benefits from implementing your CRM](https://www.g2.com/discussions/quantifiable-benefits-from-implementing-your-crm)
  - Posted at: over 13 years ago
  - Comments: 4


