Skip to content
DashboardStart deploying

Pollen config

Secrets, managed.

Encrypted at rest. Injected at boot. Versioned. Your workloads never see a plaintext secret on disk.

POLLEN SECRETSA little trust. Carefully placed.
DECLARED REFERENCEpollen://preview/service-token
Resolve at the boundary
SERVICE_TOKEN••••••••••••✓

Pollen secrets

The right secret, at the right boundary.

Secret references resolve inside the selected environment. The workload receives its values at the execution boundary.

Example secret injection · no credentials
Secretsexample-api
DATABASE_URL••••••••••••••••
SERVICE_TOKEN••••••••••••••••
Declared references
WASI environment
# Workload has not requested its secrets
No values in the component source

Deployment references

[env]
DATABASE_URL = "pollen://production/database"
SERVICE_TOKEN = "pollen://production/token"

All values in this demo are synthetic examples.

Scoped to the workload

EnvironmentProduction
InjectionNot requested

How it works

Encrypt. Store. Inject.

[ ]
01

Encrypt

Secrets are encrypted client-side before reaching the API. AES-256-GCM with per-secret key envelopes. The platform KMS manages the root keys.

||
02

Store

Encrypted payloads are persisted with version history. Every mutation is logged in the audit trail. Secrets are scoped to project and environment.

>
03

Inject

At workload boot, Nectar resolves declared secret references and injects them as WASI environment variables. No filesystem writes. No network calls from your code.

Features

Secrets done right.

Versioning

Secret Versions

Every secret update creates a new immutable version. Roll back instantly. Compare versions side by side. Audit who changed what and when.

Environments

Environment Scoping

Separate secrets per environment: dev, staging, production. Promote secrets between environments with a single command. No copy-paste.

Rotation

Automatic Rotation

Define rotation policies. Pollen generates new values, encrypts, and injects them on the next workload boot. Zero downtime rotation.

Access

Fine-grained ACLs

Control who can read, write, and rotate each secret. Scoped to teams, projects, or individual workloads. Integrated with Keystone IAM.

Secure your secrets.

Encrypted. Versioned. Injected at boot. Never on disk.

Start free →Read the docs

Hives is part of L1fe AI — infrastructure for autonomous intelligence.

Platform

  • Overview
  • How it works
  • Architecture
  • Runtime
  • Nectar
  • Queen
  • Comb
  • Stingers
  • Buzz
  • Waggle
  • Cells
  • Pollen

Solutions

  • AI agents
  • Edge functions
  • Scheduled jobs
  • Message processing
  • Webhooks
  • Real-time APIs
  • Multi-tenant SaaS
  • Fintech
  • Healthcare
  • Retail
  • Government
  • Startups

Developers

  • Docs
  • Quickstart
  • API reference
  • CLI reference
  • SDKs
  • Open source
  • Roadmap
  • Changelog
  • GitHub
  • Discord

Customers

  • Case studies
  • By industry
  • By workload
  • Partners
  • Technology partners
  • Solution partners
  • Become a partner
  • Community
  • Events
  • Champions

Company

  • About Hives
  • L1fe AI Inc.
  • Leadership
  • Mission
  • Careers
  • Press
  • Blog
  • Contact
  • Contact sales

Trust

  • Trust hub
  • Security
  • Compliance
  • Privacy
  • Responsible disclosure
  • SLA
  • DPA
  • Privacy policy

Big ideas. Good company.

Start building

© 2026 L1fe AI Inc.

PrivacyService agreementContact
Built for what comes next.