Secure Notes
Sensitive text belongs somewhere with a control model.
Passwords, recovery information, private keys, access procedures and internal instructions, protected on the device and shared only with the people the organization names.
The problem
Secrets end up wherever work happens.
Credentials get pasted into chat threads. Recovery phrases live in a personal note app. Procedures for restoring access sit in a spreadsheet that three former employees still have a copy of.
Secure Notes give that material the same protection model as protected documents: encrypted on the device, readable only by authorized members, and recorded when accessed.
- Credentials and access details for systems the organization operates.
- Recovery information and key material held by named people.
- Procedures that must survive a person leaving without being readable by everyone.
In the product
Notes with the same controls as documents.
Boundaries
What Secure Notes are not.
Secure Notes serve human-managed secrets inside human workflows. They are not a machine-secrets manager that injects credentials into application runtimes, and RED does not present them as one.
LimitationNote titles are stored as metadata. Treat titles as descriptive labels, not as part of the secret.
See it against your own environment.
Connect your own storage, protect a document, and read the recorded evidence yourself.