IBM Cloud Secrets Manager
IBM Cloud Secrets Manager is a single-tenant, dedicated secrets management service powered by HashiCorp Vault that centralizes creation, storage, leasing, and lifecycle management of secrets. Designed for organizations that require…
Compare SM tools
The same fields, shown the same way, for every SM listing — so you can compare across vendors at a glance.
| Pricing | Not provided |
| Deployment | Not specified |
| Support | Not specified |
| Compliance | ISO 27001PCI DSSGDPR |
| Automated secret/credential rotation | Yes |
| Dynamic/short-lived credentials & JIT access | Not stated |
| RBAC (role-based access control) | Not stated |
| Audit trails & logging | Yes |
| PKI / certificate management | Yes |
| CI/CD & DevOps integration | Not stated |
| Kubernetes secrets integration | Not stated |
| SSO/SCIM/SAML identity integration | Not stated |
IBM Cloud Secrets Manager is a single-tenant, dedicated secrets management service powered by HashiCorp Vault that centralizes creation, storage, leasing, and lifecycle management of secrets. Designed for organizations that require data isolation and enterprise-grade controls, Secrets Manager enables teams to create dynamic and static secrets, lease them to applications, and enforce fine-grained access policies from a single location. The service supports automatic rotation and access control, audit logging and monitoring, and integrates with IBM Cloud services to protect secrets at rest using Key Protect (including BYOK scenarios). Secrets Manager also provides built-in certificate management (SSL/TLS/PKI), HSM-backed key protection, high availability across three regional data centers, and features such as secrets groups, locks to prevent accidental modification or deletion, and customizable credential providers implemented with Code Engine jobs. Typical use cases include enforcing separation of secrets in regulated industries, centralizing multiple secret types for enterprise scale, and securely enabling automated microservice communication. Compliance attestations and integrations with IBM Cloud tooling make it suitable for financial, healthcare, and large enterprise environments that need single-tenant isolation and traceable audit trails.
Capabilities
| Single-tenant data isolation | |
| Powered by HashiCorp Vault | |
| PKI management | |
| HSM-backed key protection (HSM) | |
| Auto rotation | |
| Secrets groups for policy management | |
| Locks to prevent deletion/modification | |
| Custom credentials via Code Engine jobs | |
| Dashboard UI for API keys, credentials, and certificates | |
| Logging, monitoring and Activity Tracker audit reports | |
| High availability across regional data centers | |
| Certificates management (SSL/TLS/PKI) | |
| Integration with Key Protect for encryption (BYOK) |
Integrations
Secrets Manager integrates with IBM Cloud Toolchains and DevOps tooling for secure secret delivery, Event Notifications Service for lifecycle alerts, Key Protect for encryption key management (BYOK), Code Engine for custom credential workflows, IBM Cloud IAM for access control, and supports standard CAs such as Let’s Encrypt for certificates.
Reviews
No reviews yet.
Similar SM tools
See allBitwarden Secrets Manager is an end-to-end encrypted secrets management solution built for developer and DevOps teams to securely store, manage, and deploy infrastructure and machine credentials. It centralizes secrets in…
Keeper Secrets Manager is a fully managed, cloud-based secrets management solution designed to eliminate secrets sprawl and protect Non-Human Identities (NHIs) across CI/CD pipelines, containers, automation scripts and cloud infrastructure….
One Identity Safeguard is a comprehensive Privileged Access Management (PAM) suite designed to secure, manage and monitor privileged accounts across on-premises and cloud environments. The suite combines specialized modules —…
Aembit is a workload and non-human identity access management platform that replaces stored secrets and long-lived credentials with policy-based, just-in-time authentication for applications, services, AI agents, and MCP servers across cloud, SaaS, and on-premises environments.