# Secret Value: vault-backed resolution with BYOK and HYOK

> Secret Value resolves credentials at runtime from your own vault across six back-ends with BYOK/HYOK, so the platform never stores your secrets.

**Category:** Secrets & Credentials
**Author:** NeuralSeek Team · **Published:** June 9, 2026
**Canonical:** https://neuralseek.ai/ai-grounded/secret-value
**Section index:** https://neuralseek.ai/ai-grounded

Secret Value is one of NeuralSeek's Secrets & Credentials guardrails — part of the platform's 118 individually configurable, fully auditable controls. In regulated, high-volume AI, the difference between a system you can trust and one you merely hope works comes down to specific, tunable controls exactly like this one. Here is what Secret Value does, why it matters to the business, and how to set it for your own environment.

## What it actually does

This resolves secret values at runtime from vault back-ends — six of them, with BYOK/HYOK support. The actual credential is never stored on the platform.

## Why business teams care

Keeping secrets in your own vault, resolved only at runtime, means the platform never holds your credentials and a platform breach can't expose them. It's the strongest posture for credential security.

## How to tune it in practice

Connect the vault back-end your organization already uses and enable BYOK/HYOK where required. Rely on automated rotation and cryptographic erasure on offboarding.

## Common failure modes it prevents

Hard-coded credentials and secrets stored in plain sight are a breach waiting to happen. Secret Value closes that gap directly. By making the behavior an explicit, enforced control rather than something left to chance, it converts a latent risk into a managed, observable event — one that surfaces in the audit trail instead of in a customer complaint or a compliance finding.

## Where it fits in the stack

It governs how flows reference and resolve secrets, with values held in vault back-ends rather than on the platform. Because it lives in NeuralSeek's governance layer rather than inside any single model, the control holds identically whether a request routes to OpenAI, Anthropic, Gemini, Llama, Mistral, IBM watsonx, or an in-house model.

## Zero secrets stored on the platform

With six vault back-ends, BYOK/HYOK, automated rotation, and cryptographic erasure on offboarding, credentials stay where they belong — under your control, never the platform's.

> The safest secret is one the platform never actually holds.

## The takeaway

Secret Value resolves credentials at runtime from your own vault across six back-ends with BYOK/HYOK, so the platform never stores your secrets.

---

From NeuralSeek's AI Grounded — practical, web-verified guidance on building governed, grounded enterprise AI. NeuralSeek is the model-agnostic, governed AI platform you own: any LLM (swap with no rebuild), your data in your own tenant (cloud or on-prem), 118 guardrails enforced before any action, one container that runs anywhere.
