Unfortunately, we don't use Infisical's automated key rotation. For now, we rotate the secrets ourselves. We've not tried to improve Infisical, so I don't know if there are enhancements planned. We aim to explore using it with AI models and HCP server features implementation with Infisical. We consider having an agent that generates secrets instead of doing it manually. If a file or a secret is needed, the agent might generate it for us based on a specified pattern for the kind of secrets we want, including the length. This would be efficient, as we want to save engineering time. For example, with certificate keys already generated, we currently have to manually copy and put them into the Infisical UI. If an agent could handle that for us, it would be great.
Senior Software Engineer at a consultancy with 1-10 employees
Real User
Top 5
Jul 9, 2026
Infisical is already a strong solution for centralized secret management, but there are a few areas where it could be improved. The user experience could be made even more intuitive, especially for teams that are new to secret management platforms because more guidance steps or secret and environment migration tools would help teams onboard faster. Improving documentation with more real-world examples for different architectures such as AWS Lambda and Kubernetes, .NET applications, and multi-account cloud setups would help teams adapt best practices faster. Overall, the product direction is strong and continued improvements around automation, integration, and enterprise governance features would make it even more valuable. One area that could be improved further is automation around the full secret lifecycle. Making secret rotation more seamless with cloud services, databases, and third-party providers would reduce manual setups and improve security.
Intern at a educational organization with 501-1,000 employees
Real User
Top 20
Jun 26, 2026
I believe Infisical can be improved by adding more features. I don't think there is a specific feature missing or something I had in mind for improvement; I believe continuing on the current path and expanding what has already been done is the best course of action for Infisical.
I have not encountered any limitation in Infisical. I use the free version and have not had any limitations. It is excellent. In the way we are using it as a test, it will certainly be used as an indispensable tool in any CI/CD operation in GitHub and servers. Infisical already fully meets my needs at the moment.
DevOps Engineer at a computer software company with 11-50 employees
Real User
Top 5
Jun 20, 2026
When I use Infisical CLI tool, which is created via Go language as a Go binary, sometimes the Go binary is not updated. When we scan Infisical using the Trivy vulnerability scanning tool, we found issues with Infisical CLI Go binaries that are not updated with the latest version. Due to that, Trivy vulnerability scanning fails. Our solution is to bypass the Go binary during Infisical vulnerability scanning steps. I suggest that the Infisical team update the Go binaries in their Infisical CLI.
Programador Web Senior at a consultancy with 11-50 employees
Real User
Top 10
Jun 19, 2026
According to my experience, I see Infisical as very complete and a quite useful tool. I have no suggestions for possible improvements they could implement.
Creating multiple organizations at the same time with the pricing plan, instead of creating a very limited amount of organizations, would be a plus point for improvement. There is a limitation on how many people can be given access for a particular organization or project, which is another area that could be improved. From a features perspective, there is a little lag when running projects and importing particular secret variables. Requests to log in occur in quick succession, where sometimes it happens every five days or every ten days, which does occur from time to time, though not that frequently. Continuous logins take place after using or importing secret variables multiple times, and that is one area for improvement. Another improvement needed is the limited number of people that can be added to a particular organization to access the secret variables.
Full Stack Engineer at Marathwada Mitra Mandal's Institute of Technology
Real User
Top 20
Jun 1, 2026
One thing that kept frustrating me was that sometimes Infisical was not working from our cloud machine. We had to manually look into the workflow and run the workflow again by pasting the token. Sometimes Infisical was not working, and I do not know what was the reason, but it may have been on the Infisical side rather than on our side. The workflow was breaking because the system was not able to contact Infisical, so we had to manually rerun this, and then it would work.I would like to add more about needed improvements. One feature that I would like to see, or that is actually already a feature, is permission management. Permission management is a bit confusing in Infisical, and it took us a lot of time to clear out the permission issues. I faced many permission issues, so I had to go back and forth with my founder to get all the permissions required for building the CI/CD pipeline and injecting the tokens into it.
Infisical provides a comprehensive solution for managing secret keys and sensitive data, streamlining security processes for businesses. Designed for efficiency, Infisical ensures the protection of data and facilitates better data management workflows.Infisical caters to businesses aiming to secure their sensitive information by offering a robust infrastructure for managing encryption keys and secret data. The system integrates seamlessly into existing workflows, providing specialized...
Unfortunately, we don't use Infisical's automated key rotation. For now, we rotate the secrets ourselves. We've not tried to improve Infisical, so I don't know if there are enhancements planned. We aim to explore using it with AI models and HCP server features implementation with Infisical. We consider having an agent that generates secrets instead of doing it manually. If a file or a secret is needed, the agent might generate it for us based on a specified pattern for the kind of secrets we want, including the length. This would be efficient, as we want to save engineering time. For example, with certificate keys already generated, we currently have to manually copy and put them into the Infisical UI. If an agent could handle that for us, it would be great.
Infisical is already a strong solution for centralized secret management, but there are a few areas where it could be improved. The user experience could be made even more intuitive, especially for teams that are new to secret management platforms because more guidance steps or secret and environment migration tools would help teams onboard faster. Improving documentation with more real-world examples for different architectures such as AWS Lambda and Kubernetes, .NET applications, and multi-account cloud setups would help teams adapt best practices faster. Overall, the product direction is strong and continued improvements around automation, integration, and enterprise governance features would make it even more valuable. One area that could be improved further is automation around the full secret lifecycle. Making secret rotation more seamless with cloud services, databases, and third-party providers would reduce manual setups and improve security.
I believe Infisical can be improved by adding more features. I don't think there is a specific feature missing or something I had in mind for improvement; I believe continuing on the current path and expanding what has already been done is the best course of action for Infisical.
I have not encountered any limitation in Infisical. I use the free version and have not had any limitations. It is excellent. In the way we are using it as a test, it will certainly be used as an indispensable tool in any CI/CD operation in GitHub and servers. Infisical already fully meets my needs at the moment.
When I use Infisical CLI tool, which is created via Go language as a Go binary, sometimes the Go binary is not updated. When we scan Infisical using the Trivy vulnerability scanning tool, we found issues with Infisical CLI Go binaries that are not updated with the latest version. Due to that, Trivy vulnerability scanning fails. Our solution is to bypass the Go binary during Infisical vulnerability scanning steps. I suggest that the Infisical team update the Go binaries in their Infisical CLI.
According to my experience, I see Infisical as very complete and a quite useful tool. I have no suggestions for possible improvements they could implement.
Creating multiple organizations at the same time with the pricing plan, instead of creating a very limited amount of organizations, would be a plus point for improvement. There is a limitation on how many people can be given access for a particular organization or project, which is another area that could be improved. From a features perspective, there is a little lag when running projects and importing particular secret variables. Requests to log in occur in quick succession, where sometimes it happens every five days or every ten days, which does occur from time to time, though not that frequently. Continuous logins take place after using or importing secret variables multiple times, and that is one area for improvement. Another improvement needed is the limited number of people that can be added to a particular organization to access the secret variables.
One thing that kept frustrating me was that sometimes Infisical was not working from our cloud machine. We had to manually look into the workflow and run the workflow again by pasting the token. Sometimes Infisical was not working, and I do not know what was the reason, but it may have been on the Infisical side rather than on our side. The workflow was breaking because the system was not able to contact Infisical, so we had to manually rerun this, and then it would work.I would like to add more about needed improvements. One feature that I would like to see, or that is actually already a feature, is permission management. Permission management is a bit confusing in Infisical, and it took us a lot of time to clear out the permission issues. I faced many permission issues, so I had to go back and forth with my founder to get all the permissions required for building the CI/CD pipeline and injecting the tokens into it.