SIG Lite Control APP-07 Extractive Review Standard

How to answer 'How are API keys and database secrets injected into production applications?' on a SIG Lite

Reviewer Guidance & Pitfalls

State that secrets are never checked into version control, are injected dynamically at runtime via environment variables from dedicated secrets managers, and are encrypted at rest.

Example Answer Passing Enterprise Audit

Compliant Response Template
Application secrets are stored in encrypted cloud secret vaults and injected as runtime environment variables into container tasks; repository scanning prevents secrets from entering git history (SOC 2, CC6.1).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.