How Alphonso Scaled Secrets Management, Implemented Dynamic Secrets, and Supported SOC 2 Compliance
Streamlining secrets management across Kubernetes, Databricks, and modern infrastructure.
Looking to improve your secret management processes?Talk to an expert
“With Infisical, secrets management is just out of the engineers’ minds. They don’t have to worry about storing them. It’s all done for them. And if there are rotations, it’s done for them as well.”— Corey Mudd, DevOps and QA Engineer, Alphonso
Key Results
- Automated central secrets management across engineering teams
- Improved developer experience by making secrets something they don’t have to think about.
- Adopted advanced security practices like dynamic secrets rotations in complex Kubernetes deployments
The goal: centralizing secrets management at scale
With its LG Ad Solutions brand, Alphonso Inc. is an advertising technology company and majority owned by LG Electronics, operating an AI-powered platform for connected TV and cross-screen advertising. At their scale, the network includes 49 million LG Smart TVs in the US and 216 million globally, so infrastructure complexity compounds fast.
As the organization expanded, Alphonso sought to unify and standardize secrets management across different teams and environments.
To support their growing ecosystem, the team looked to implement a dedicated platform tailored for modern secrets management:
- Providing a unified dashboard to manage secret access, visibility, and auditing across teams.
- Automating secret rotations, lifecycle management, and environment isolation seamlessly.
“We wanted a central platform to streamline how credentials are managed and rotated across teams,” said Corey Mudd, DevOps and QA Engineer at Alphonso.
As Alphonso worked to strengthen its security posture, enhancing infrastructure automation and establishing automated secret rotation, comprehensive audit logging, fine-grained RBAC, and clean environment isolation became key priorities.
Alphonso started to evaluate secrets managers and ultimately landed on Infisical.
The solution: Why Infisical won the evaluation
The team evaluated several options. Compatibility with their infrastructure was essential, and Infisical became their vendor of choice because of its native support of dynamic secrets and automated secret rotations, which are two secrets management best practices.
Pricing transparency was another factor. Per-call or per-secret pricing models can disincentivize good security practices. When every rotation and every secret access costs money, teams can drift towards less optimal security practices to lower costs.
Alphonso wanted to rotate credentials frequently and generate dynamic secrets on the fly to cut off the lateral movement risk that static, long-lived credentials create.
“The overriding factor was that dynamic credential rotation. That was the tipping point,” Corey said.
The results: Kubernetes secrets management DevOps doesn’t worry about
Alphonso runs a Kubernetes-heavy infrastructure. The Infisical Kubernetes Operator fit directly into how they were already working. Before Infisical, secrets had to be manually sourced from etcd and fed into pods. This process meant any rotation required tracking down every engineer and non-human identity by hand, which caused operational friction.
Infisical’s Kubernetes Operator syncs secrets into native Kubernetes Secret objects. Now, pod configurations stay clean and rotated values propagate automatically, without redeployments, manual handoffs, or hunting across environments to find what broke.
For data engineering, Infisical handles automatic rotation for Databricks Service Principals. It turned a manual credential handoff between DevOps and data engineering to an automated background process.
Structurally, there’s now a clear ownership model:
- DevOps owns the central provisioning layer, while the security team sets best practices and ensures compliance.
- App teams (whose engineers ultimately use the secrets) use credentials through Infisical without managing the underlying infrastructure or, in many cases, even knowing the secrets.
As a result, secrets no longer create operational friction and everyone’s work is easier.
How Infisical improved developer experience
The most important outcome is that engineers no longer think about secrets.
“It’s just out of their minds,” Corey said. “They don’t have to worry about storing them. It’s all done for them. And if there are rotations, it’s done for them as well.”
With security tools like secrets managers, no news is good news: it means security isn’t getting in the way of building. And engineers almost never ping Corey about Infisical. For a DevOps engineer, that’s a significant benefit. The team now runs secrets through Infisical as a centralized solution.
This works because Infisical covers every part of their secrets workflow across environments without workarounds. This is possible in part because of Infisical’s support. Compatibility with an older Java package was resolved in under a week, and questions are answered quickly on Slack.
“When we do have a question or problem, we’re able to get a response not even just within a day, but within minutes,” Corey said.
Key outcomes
- Centralized Secrets Management: Adopted a dedicated secrets management platform with comprehensive audit logging, RBAC, and automated rotation.
- Streamlined Access & Visibility: Established a unified platform for managing all secrets and access policies across teams.
- Automated Kubernetes secret delivery via the Infisical Kubernetes Operator, syncing secrets as native Kubernetes objects without manual handoffs or redeployments.
- Automated Databricks Service Principal rotation, replacing manual credential handoffs between DevOps and data engineering.
- Supported SOC 2 Compliance using Infisical as a foundational control for automated rotation, audit logging, RBAC, and environment isolation.
Infisical: Secrets Management for Teams That Want to Move Fast
When secrets management gets in the way, fast-moving teams either slow down or take shortcuts. Infisical gives engineering teams a system that works in the background, with the controls and self-hosted flexibility that hold up as the team grows.
Want to see how it would work in your environment? Get a demo of Infisical or sign up to try it for free.
Starting with Infisical is simple, fast, and free.