Secrets Management & Key Vault Infrastructure3 min readUpdated September 2026

Standardizing Secrets Across a PE Roll-Up's Portfolio Companies

A lower-middle-market roll-up inherits a different secrets problem with every add-on acquisition. Each company arrives with its own habits, some disciplined, some running on a single shared administrator password nobody's changed since founding. Standardizing that mess matters more to the platform's eventual exit than most operating partners realize during the first hundred days.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

The Problem a Roll-Up Inherits: Five Companies, Five Different Habits

Every acquired company brings its own IT vendor, its own password conventions, and often its own undocumented shared logins that outlived the employees who set them up. Left alone, a platform ends up managing five incompatible approaches to the same problem, which makes it nearly impossible to answer a simple question like who has access to what across the whole portfolio.

What the 100-Day Plan Should Actually Ask About Secrets

During integration planning, get a straight answer from each acquired company on where credentials are stored today, who currently has access, and whether any of them are shared across systems that should be separated. This inventory, done early, is what makes standardization possible later instead of a permanent patchwork.

Questions to ask each acquired company during integration planning:

  • Where are credentials stored today, and is that location documented anywhere outside one person's memory?
  • Who currently has access to those credentials, including former employees and outside IT vendors who may still hold logins?
  • Are any credentials shared across systems that should be kept separate, such as a single administrator password used everywhere?
  • Which credentials were ever shared with the parent platform's other companies or central IT, and how would they be cut over cleanly?

When does Doppler fit a fast standardization push?

Doppler's quick setup lets a platform bring a newly acquired company onto a consistent secrets structure within weeks of close, without needing to stand up shared infrastructure first. For a roll-up moving through several add-ons a year, that speed matters more than any single advanced feature.

When does Vault fit once you centralize infrastructure across portcos?

Once the platform starts consolidating infrastructure across multiple portfolio companies, sharing a data warehouse or a common application layer, Vault's namespace model lets each portco keep its own scoped access while the platform team manages shared policy centrally. A portfolio company that has to fund an emergency credential rotation across newly acquired systems is spending capital that shows up in the same burn multiple a board tracks between funding rounds1.

What the Board or Audit Committee Will Want to See Before Exit

A buyer's diligence team will eventually ask how credential access is managed across the portfolio, and an inconsistent answer across companies is a flag worth avoiding. Standardized rotation evidence, presented the same way for every portfolio company, is a small detail that makes the rest of your diligence package look considerably more credible.

A Common Mistake: Treating a Not-Yet-Integrated Company as Lower Risk

It's easy to deprioritize secrets hygiene at a recently acquired company that hasn't been fully integrated into the platform yet, on the reasoning that it's still running semi-independently and therefore lower priority. That reasoning gets the risk backwards: an unintegrated company often still has its pre-acquisition habits fully intact, including whatever shared or default credentials existed before the deal closed.

Inventory and address the acquired company's existing credentials early, even before deeper systems integration begins, rather than waiting for integration to reach that workstream naturally. The gap between close and full integration is often when a legacy credential is most likely to be exploited, precisely because attention is elsewhere.

A Decision Rule for Prioritizing Which Portco to Standardize First

With several acquired companies competing for the platform's limited security attention, prioritize by exposure, not by acquisition date. A recently acquired company still running its pre-deal shared administrator credential is a higher priority than an older portco that's already been through one standardization pass, even if the older one closed first.

A simple scoring approach works well enough: for each portco, note whether default or shared credentials are still in use, whether any rotation has happened since close, and how much of that company's infrastructure is now shared with the rest of the platform. Address the highest-exposure company first, then work down the list rather than proceeding strictly in acquisition order.

Untangling Shared Credentials When a Portco Is Carved Out or Sold

When a portfolio company is sold or spun out, either to a strategic buyer or back to its own management team, someone has to figure out which of its credentials were ever shared with the parent's other companies or with the platform's central IT, and cut those over cleanly.

This is harder than it sounds if the portco's secrets were ever stored in a shared Vault instance or a Doppler team spanning multiple companies in the portfolio, rather than isolated per entity from the start. Untangling shared access after the fact, under a closing deadline, is far more work than isolating it would have been on day one of the acquisition.

Ask this question during diligence on the way in, not just on the way out: if this company were sold tomorrow, how long would it take to prove that none of its credentials still live inside another portfolio company's systems?

Executive Capability Standard

What Good Looks Like

A roll-up can name every credential each acquired company still uses within its first hundred days of ownership, replace shared or default logins before the next add-on closes, and show a board the same rotation evidence across every portfolio company, not just the original one.

Building The Capability (5-Stage Skill Ladder)

1. Learn:During diligence or the first thirty days after close, inventory every credential the acquired company's team still holds.
2. Do Manually:Track each portfolio company's credentials separately and rotate anything shared or default by hand after close.
3. Delegate:Assign the platform team's security lead ownership of credential standardization across every portfolio company.
4. Automate:Move every portfolio company onto the same Doppler or Vault setup so rotation evidence looks identical across the portfolio.
5. Buy:Centralize secrets management at the platform level with per-portco scoping, so a board can review one consistent report instead of five different ones.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

Should an acquired company's existing secrets tool be replaced immediately after close?

Not necessarily immediately, but it should be inventoried and evaluated against your platform standard within the first few months. Replacing it too early, before you understand what depends on it, risks breaking systems the acquired company relies on before you've mapped those dependencies.

How does secrets hygiene affect due diligence at exit?

A buyer's technical diligence team will look at access control and credential management as part of assessing operational risk across the portfolio. Consistent, documented practices across every portfolio company make that part of diligence move faster and raise fewer follow-up questions.

Who should own secrets access across multiple portfolio companies, the platform team or each portco?

A common pattern is platform-level ownership of the standard and shared infrastructure, with each portco's own team managing day-to-day access within that standard. This keeps consistency without forcing every operational decision through a central team that doesn't know each business as well.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Burn multiple guidance bands by ARR (net burn / net new ARR). a16z Growth burn multiple framework (Kahl & George, 'A Framework for Navigating Down Markets', May 2022), table transcribed by Kruze Consulting, 2022.

Related Guides