@graaff Given the amount of people we have and services we depend on, this is all handled per service. Personal and shared credentials are handled in 1Password. For critical credentials and software signing we have a Yubikey-based process.
"Fun” fact: our security posture is pretty strong, but we don’t have a formally documented and verified process and thus no ISO27001 certification. This is becoming increasingly problematic dealing with (potential) customers. #DigitalSovereignty #OpenSource