As the vault is being deprecated, we are willing to replace it by encrypted KVMs as recemmended. With vault we are accessing entries using a python script policy. Is it possible to do this with encrypted KVMs? If yes, could you please give an example?