Standardizing Secrets Across a PE Roll-Up's Portfolio Companies
A lower-middle-market roll-up inherits a different secrets problem with every add-on acquisition. Each company arrives with its own habits, some disciplined, some running on a single shared administrator password nobody's changed since founding. Standardizing that mess matters more to the platform's eventual exit than most operating partners realize during the first hundred days.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
The Problem a Roll-Up Inherits: Five Companies, Five Different Habits
Every acquired company brings its own IT vendor, its own password conventions, and often its own undocumented shared logins that outlived the employees who set them up. Left alone, a platform ends up managing five incompatible approaches to the same problem, which makes it nearly impossible to answer a simple question like who has access to what across the whole portfolio.
What the 100-Day Plan Should Actually Ask About Secrets
During integration planning, get a straight answer from each acquired company on where credentials are stored today, who currently has access, and whether any of them are shared across systems that should be separated. This inventory, done early, is what makes standardization possible later instead of a permanent patchwork.
Questions to ask each acquired company during integration planning:
- Where are credentials stored today, and is that location documented anywhere outside one person's memory?
- Who currently has access to those credentials, including former employees and outside IT vendors who may still hold logins?
- Are any credentials shared across systems that should be kept separate, such as a single administrator password used everywhere?
- Which credentials were ever shared with the parent platform's other companies or central IT, and how would they be cut over cleanly?
When does Doppler fit a fast standardization push?
Doppler's quick setup lets a platform bring a newly acquired company onto a consistent secrets structure within weeks of close, without needing to stand up shared infrastructure first. For a roll-up moving through several add-ons a year, that speed matters more than any single advanced feature.
When does Vault fit once you centralize infrastructure across portcos?
Once the platform starts consolidating infrastructure across multiple portfolio companies, sharing a data warehouse or a common application layer, Vault's namespace model lets each portco keep its own scoped access while the platform team manages shared policy centrally. A portfolio company that has to fund an emergency credential rotation across newly acquired systems is spending capital that shows up in the same burn multiple a board tracks between funding rounds1.
What the Board or Audit Committee Will Want to See Before Exit
A buyer's diligence team will eventually ask how credential access is managed across the portfolio, and an inconsistent answer across companies is a flag worth avoiding. Standardized rotation evidence, presented the same way for every portfolio company, is a small detail that makes the rest of your diligence package look considerably more credible.
A Common Mistake: Treating a Not-Yet-Integrated Company as Lower Risk
It's easy to deprioritize secrets hygiene at a recently acquired company that hasn't been fully integrated into the platform yet, on the reasoning that it's still running semi-independently and therefore lower priority. That reasoning gets the risk backwards: an unintegrated company often still has its pre-acquisition habits fully intact, including whatever shared or default credentials existed before the deal closed.
Inventory and address the acquired company's existing credentials early, even before deeper systems integration begins, rather than waiting for integration to reach that workstream naturally. The gap between close and full integration is often when a legacy credential is most likely to be exploited, precisely because attention is elsewhere.
A Decision Rule for Prioritizing Which Portco to Standardize First
With several acquired companies competing for the platform's limited security attention, prioritize by exposure, not by acquisition date. A recently acquired company still running its pre-deal shared administrator credential is a higher priority than an older portco that's already been through one standardization pass, even if the older one closed first.
A simple scoring approach works well enough: for each portco, note whether default or shared credentials are still in use, whether any rotation has happened since close, and how much of that company's infrastructure is now shared with the rest of the platform. Address the highest-exposure company first, then work down the list rather than proceeding strictly in acquisition order.
Untangling Shared Credentials When a Portco Is Carved Out or Sold
When a portfolio company is sold or spun out, either to a strategic buyer or back to its own management team, someone has to figure out which of its credentials were ever shared with the parent's other companies or with the platform's central IT, and cut those over cleanly.
This is harder than it sounds if the portco's secrets were ever stored in a shared Vault instance or a Doppler team spanning multiple companies in the portfolio, rather than isolated per entity from the start. Untangling shared access after the fact, under a closing deadline, is far more work than isolating it would have been on day one of the acquisition.
Ask this question during diligence on the way in, not just on the way out: if this company were sold tomorrow, how long would it take to prove that none of its credentials still live inside another portfolio company's systems?
What Good Looks Like
A roll-up can name every credential each acquired company still uses within its first hundred days of ownership, replace shared or default logins before the next add-on closes, and show a board the same rotation evidence across every portfolio company, not just the original one.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Gives a board consistent evidence across portfolio companies instead of five different self-reported answers.
An alternative to Vanta for tying rotation evidence to each portfolio company's own cloud account automatically.
Relevant once a portfolio company's infrastructure runs on AWS and needs IAM-scoped access standardized across the portfolio.
Frequently Asked Questions
Should an acquired company's existing secrets tool be replaced immediately after close?
Not necessarily immediately, but it should be inventoried and evaluated against your platform standard within the first few months. Replacing it too early, before you understand what depends on it, risks breaking systems the acquired company relies on before you've mapped those dependencies.
How does secrets hygiene affect due diligence at exit?
A buyer's technical diligence team will look at access control and credential management as part of assessing operational risk across the portfolio. Consistent, documented practices across every portfolio company make that part of diligence move faster and raise fewer follow-up questions.
Who should own secrets access across multiple portfolio companies, the platform team or each portco?
A common pattern is platform-level ownership of the standard and shared infrastructure, with each portco's own team managing day-to-day access within that standard. This keeps consistency without forcing every operational decision through a central team that doesn't know each business as well.
Sources
Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.
- Burn multiple guidance bands by ARR (net burn / net new ARR). a16z Growth burn multiple framework (Kahl & George, 'A Framework for Navigating Down Markets', May 2022), table transcribed by Kruze Consulting, 2022.
Related Guides
Database Infrastructure for Lower-Middle-Market PE Portfolio Companies
Lower-middle-market PE portfolio companies rolling up acquisitions need consistent, diligence-ready database infrastructure. Here's the comparison.
One Identity Vendor or Many Across a PE Portfolio
A decision guide for lower-middle-market PE portfolio companies weighing Auth0 versus Clerk, and whether to standardize the choice across the portfolio.
Standardizing Feature Flags Across a PE Portfolio's Portcos
A PE platform integrating several lower-middle-market portfolio companies benefits from one flag standard. Comparing LaunchDarkly and Split at that level.
CrowdStrike vs SentinelOne for PE Portfolio Companies
A portco's endpoint fleet is usually several acquired companies' fleets stitched together. A worked example for standardizing on CrowdStrike or SentinelOne.
SOC 2 Across a PE Portfolio: Vanta, Drata or Secureframe
How a private equity firm should think about rolling SOC 2 out across lower-middle-market portfolio companies, and where Vanta, Drata and Secureframe each fit.
A Post-Close Security Worksheet for PE Portfolio Companies
A worksheet for standardizing Snyk or GitHub Advanced Security across a private equity portfolio company's engineering team after close.