Please consider some sort of access log for all activity around the secrets you’re managing, exposed to users in their account. Also consider a way to revoke all secrets/tokens at once with a privileged (MFA authorized) user action.
Best of luck, I think this product has a lot of value ahead based on the pain points addressed.
Best of luck, I think this product has a lot of value ahead based on the pain points addressed.
EDIT: This might also be of use before your SOC 2: https://latacora.singles/2020/03/12/the-soc-starting.html