IBM Cloud Secrets Manager

Overview

IBM Cloud Secrets Manager is a single-tenant, dedicated secrets management service powered by HashiCorp Vault that centralizes creation, storage, leasing, and lifecycle management of secrets. Designed for organizations that require data isolation and enterprise-grade controls, Secrets Manager enables teams to create dynamic and static secrets, lease them to applications, and enforce fine-grained access policies from a single location. The service supports automatic rotation and access control, audit logging and monitoring, and integrates with IBM Cloud services to protect secrets at rest using Key Protect (including BYOK scenarios). Secrets Manager also provides built-in certificate management (SSL/TLS/PKI), HSM-backed key protection, high availability across three regional data centers, and features such as secrets groups, locks to prevent accidental modification or deletion, and customizable credential providers implemented with Code Engine jobs. Typical use cases include enforcing separation of secrets in regulated industries, centralizing multiple secret types for enterprise scale, and securely enabling automated microservice communication. Compliance attestations and integrations with IBM Cloud tooling make it suitable for financial, healthcare, and large enterprise environments that need single-tenant isolation and traceable audit trails.

Features

  • Single-tenant data isolation
  • Powered by HashiCorp Vault
  • PKI management
  • HSM-backed key protection (HSM)
  • Auto rotation
  • Secrets groups for policy management
  • Locks to prevent deletion/modification
  • Custom credentials via Code Engine jobs
  • Dashboard UI for API keys, credentials, and certificates
  • Logging, monitoring and Activity Tracker audit reports
  • High availability across regional data centers
  • Certificates management (SSL/TLS/PKI)
  • Integration with Key Protect for encryption (BYOK)

Integrations

Secrets Manager integrates with IBM Cloud Toolchains and DevOps tooling for secure secret delivery, Event Notifications Service for lifecycle alerts, Key Protect for encryption key management (BYOK), Code Engine for custom credential workflows, IBM Cloud IAM for access control, and supports standard CAs such as Let’s Encrypt for certificates.

Popular integrations

Compliance & Certifications

ISO 27001 PCI DSS GDPR

Sellers & Vendors

🏢

IBM

IBM (International Business Machines Corporation) is a global technology and consulting company known for its innovations in computing, artificial intelligence, and enterprise solutions. IBM has a long history of pioneering technology advancements and providing IT services and products to businesses around the world.

newsletter background