# Secrets

> For the complete documentation index, see [llms.txt](https://docs.redpanda.com/llms.txt). Component-specific: [cloud-data-platform-full.txt](https://docs.redpanda.com/cloud-data-platform-full.txt)

---
title: Secrets
latest-operator-version: v26.1.4
latest-console-tag: v3.7.3
latest-connect-version: 4.93.0
latest-redpanda-tag: v26.1.9
docname: secrets
page-component-name: cloud-data-platform
page-version: master
page-component-version: master
page-component-title: Cloud
page-relative-src-path: secrets.adoc
page-edit-url: https://github.com/redpanda-data/cloud-docs/edit/main/modules/security/pages/secrets.adoc
description: Learn how Redpanda Cloud manages secrets.
page-git-created-date: "2024-06-06"
page-git-modified-date: "2024-08-01"
---

<!-- Source: https://docs.redpanda.com/cloud-data-platform/security/secrets.md -->

Redpanda Cloud uses _dynamic secrets_ through IAM roles. These have policies defined by the actions and resources that a user (also known as a principal) strictly needs, following the principle of least privilege.

Redpanda Cloud also uses _static secrets_, stored in either the [AWS Secrets Manager](https://aws.amazon.com/secrets-manager/) or [GCP Secret Manager](https://cloud.google.com/secret-manager) services. Static secrets managed through Redpanda Console never leave their corresponding data plane account or network. They stay securely stored in AWS Secrets Manager or GCP Secret Manager.