In 2018, Brian Vallelunga was working on a personal project and kept running into a task that ought to have been dull: managing secrets. The name sounds theatrical. The objects are ordinary - API keys, database passwords, certificates, and tokens that let one piece of software talk to another. Without them, the application cannot work. With them in the wrong place, it can work for somebody else.
Vallelunga had worked as a software engineer at Uber. When he asked around, he found the same irritation at well-funded companies and among hobbyists. The problem was not that engineers had forgotten how to make passwords. It was that a credential had to follow an application through local development, testing, deployment, and several clouds, while remaining both available and controlled. A little .env file was pleasant to use until there were thirty of them, several people editing them, and no trustworthy account of which one was current.
- Doppler keeps application credentials in one managed place and delivers them to the tools that need them.
- Its customers are engineering and security teams, from startups to large organizations.
- The distinctive product is the workflow around a secret: access, approval, rotation, sync, and a record of the change.
Vallelunga started Doppler that year. The company was eventually backed by Sequoia, Kleiner Perkins, GV, Y Combinator, and CRV. Its 2022 Series A raised $20 million. Money buys time to build a platform; it does not explain why anyone would enjoy using one. Doppler's answer was to make security behave more like an everyday engineering tool. The company calls the ambition “SecretOps,” a phrase that is less interesting than the practical question behind it: can a developer change a key without staging a small bureaucratic opera?

A vault is only the beginning
Doppler offers a dashboard, command-line tool, API, and integrations that organize secrets by project and environment. A developer can run an application locally with the right credentials. A pipeline can receive its own scoped access. A production service can get an updated value without someone copying it through chat. The platform connects to tools including Kubernetes, GitHub Actions, Vercel, AWS Secrets Manager, and Azure Key Vault. For a team using several of these at once, the point is the handoff between them.
That is where Doppler positions itself against HashiCorp Vault and the secret stores built into individual clouds. Those products can store credentials. Doppler argues that teams also need a usable way to review a change, distribute the new value, see where it went, and retire the old one. Its current product includes secret references, automated rotation, short-lived dynamic credentials, access controls, and activity logs. A company can use Doppler as its central store or sync from it into cloud secret managers; the architecture depends on where applications already live.
The economics are similarly pragmatic. Doppler has a free Developer tier, a $21-per-user-per-month Team tier listed on its public pricing page, and custom Enterprise plans. The company says machine identities and AI agents do not add per-agent charges. Higher tiers add features such as SSO, longer logs, policy controls, dynamic secrets, and on-prem deployment. A free tool can get a developer started; the bill arrives when a team needs to coordinate and govern the work.
Nineteen steps to change one thing
The clearest account of what Doppler does comes from Ada, an AI customer-service company. Ada had built its own secrets system around KMS encryption and Git when it was a smaller, colocated team. As the company grew and worked remotely, the process spread across GitHub pull requests, Slack messages, and approval tickets. Its case study says a production change took 19 steps and could consume hours. Ada looked at Vault, AWS Secrets Manager, and Akeyless. It wanted an interface, command-line tool, permissions, and approvals without building more internal glue.
Ada tried Doppler in its largest, most complex Python service. This was a deliberately consequential test: if the process worked there, smaller services would be easier to bring along. Its team then made a Doppler project part of the default setup for new services and connected provisioning to Okta. Production changes could be proposed and approved inside Doppler. In Ada's account, the 19-step procedure became one workflow, and the whole engineering organization adopted it.
“We wanted to spend less time managing secrets and more time on our core dev work.”Ada engineering team
There is a lesson here for a reader without a secrets company in the story. First list every place a production key lives. Count the people and approvals needed to change it. Try the new process on a service that has enough complexity to reveal the awkward parts. Then decide whether it deserves to become the default. A demo with a toy application cannot answer the question Ada actually had.

The cost of the old habit
The Children's Cancer Institute in Australia offers a different measure. Its case study says engineers managed more than 1,300 secrets and used static, unencrypted files on developer machines. After adopting Doppler, the institute reported that daily secrets work fell from about an hour to two minutes, while new engineer onboarding fell from eight hours to four. These are customer-reported results, not a universal rate of return. They do show why a research organization might care about a developer tool: every minute spent repairing configuration is a minute unavailable for its actual work.
AgentSync, an insurance software company, reported a 75% reduction in AWS Secrets Manager usage after moving secrets into Doppler and said its broader AWS spend fell 10%. That result depends on its prior cloud bill, its number of secrets, and the labor involved in maintaining them. A team with one application and a tidy existing setup may see far less financial gain. The more compelling argument is often operational: fewer copies, clearer ownership, and a tested path for changing a credential under pressure.
Now the users are machines
Doppler's market has shifted since its first pitch to developers. Pipelines, service accounts, containers, and AI agents all need credentials. Unlike a human employee, a machine identity may be created for a short task, gain broad access, and then linger after the task disappears. The company now talks about governing these non-human identities as much as storing API keys. Recent updates added Azure Service Principal rotation, temporary Azure credentials, and more OIDC and Terraform controls.
The promise is attractive, but it requires discipline from the buyer. Centralizing secrets does not inventory every forgotten credential by magic. Automated rotation still has to account for services that cache old values. Short-lived credentials require applications that can renew them. If a team cannot name the owner of a key or test how its dependent services react to a change, a new dashboard merely gives the confusion a nicer address.
In its first years, Doppler said it grew from 600 secrets served each month to more than 11 billion. Its current site reports more than 75 billion monthly secret reads. Those figures measure different things, but together they show the distance between a personal project's annoying file and a piece of working infrastructure. Vallelunga's original observation still holds: developers will protect the keys more reliably when the routine for doing so fits the way they already build software. The file was tiny. The habit around it was the product.