Keyvaci

Blog · Playbook · 16 August 2026

A credential breach just hit the news.
Your first 24 hours.

Every few months a breach makes headlines and every team asks the same question: are we affected, and what do we do first? Keep this playbook. It is written to be run under pressure, and it works whether or not you use Keyvaci.

Hour 0 to 2: decide whether you are exposed

  1. Name the asset precisely. "Vendor X breached" matters only if you hold accounts, credentials, tokens, or data at vendor X, or reuse passwords that lived there. Write down the actual overlap before acting.
  2. Check reuse, not just presence. The blast radius of any leak is wherever the same password or a close variant was reused. If your credentials live in a searchable team vault, this query takes minutes; if they live in chat threads and spreadsheets, this step is your bottleneck and your lesson.
  3. Freeze convenience access. Pause any browser-extension autofill or shared session for the affected domain until rotation is done.

Hour 2 to 12: rotate in priority order

Do not rotate alphabetically. Rotate by damage potential:

  1. Credentials that move money: banking, payment processors, payroll.
  2. Identity roots: domain registrar, DNS, the admin accounts of your identity provider itself.
  3. Infrastructure roots: cloud accounts, CI/CD, code hosting.
  4. Long-lived machine secrets: API keys and tokens, which never expire on their own and are exactly what AI agents and integrations tend to hold.
  5. Everything else the leak touches.

After each rotation, revoke active sessions and refresh tokens where the service allows it; a rotated password does not log out a live attacker.

Hour 12 to 24: prove it and say it

  • Prove completion from records, not memory. An append-only audit log answers "who accessed this credential recently, and did anyone touch it after the news broke?" without interviews. This is the moment audit trails are for.
  • Tell your team what changed and, if customer data was in scope, follow your notification obligations rather than your comfort level.
  • Schedule the postmortem within a week: which step was slow, which credential had no owner, what gets fixed.

The uncomfortable question the news is asking you

Every headline breach is also a question about your own vendor: if they were breached instead, what would the attacker have? If the honest answer is "our plaintext", the fix is architectural, not procedural. A zero-knowledge vault changes the answer to "ciphertext they cannot open", which is why we built Keyvaci so that even we cannot read what you store. Rotation drills still matter; needing them less is better.

Make the next headline someone else's fire drill

14 days, every feature, no credit card. Sign in with company SSO or a plain email address.