Try our new research platform with insights from 80,000+ expert users

AWS Secrets Manager vs BeyondTrust Password Safe comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Secrets Manager
Ranking in Enterprise Password Managers
2nd
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
15
Ranking in other categories
No ranking in other categories
BeyondTrust Password Safe
Ranking in Enterprise Password Managers
7th
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
26
Ranking in other categories
Privileged Access Management (PAM) (9th)
 

Mindshare comparison

As of September 2025, in the Enterprise Password Managers category, the mindshare of AWS Secrets Manager is 16.5%, down from 21.3% compared to the previous year. The mindshare of BeyondTrust Password Safe is 3.6%, up from 3.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Enterprise Password Managers Market Share Distribution
ProductMarket Share (%)
AWS Secrets Manager16.5%
BeyondTrust Password Safe3.6%
Other79.9%
Enterprise Password Managers
 

Featured Reviews

Mahadev Metre - PeerSpot reviewer
Consistent security and efficiency improvements optimize IT infrastructure with effective management
When creating AWS Secrets Manager, it should be automated using tools such as Terraform, Puppet, or Ansible. With Terraform code, you specify the encryption key, secret name, rotation policy, and secret replication. Human error occurs when feeding secret values manually, especially with large amounts of secrets to input. Secrets should never be protected only by IAM. They should be protected by multiple layers, such as IAM and one or two KMS keys. Additional security measures could be beneficial if necessary. The rotation policy is crucial because some secrets may become obsolete, require updates, or get compromised. With a weekly rotation policy, if unauthorized access occurs, the exposure is limited to seven days. The rotation policy can be customized according to needs.
IshtiaqKhalil - PeerSpot reviewer
Extensive experience with session management and quick technical support boost confidence
While generally a strong product, BeyondTrust Password Safe has a few areas that could use some polish. From an administrator's viewpoint, we sometimes see keystroke capturing fail. More significantly, RDP sessions occasionally disconnect without any error messages on the client side. This leaves us administrators in the dark, unable to identify the cause of the problem

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Secrets Manager helps in retrieving the enrollment variables used by the code."
"The most valuable feature of AWS Secrets Manager is the ability to keep data secret and assign access permissions to people to grant or restrict access."
"I would highly recommend AWS Secrets Manager for secret management in AWS."
"AWS Secrets Manager plays a significant role in optimizing IT infrastructure security and efficiency."
"It's highly scalable, so I'd rate it a ten out of ten."
"All our workloads are running on AWS, so integration with our workload is much easier on AWS Secrets Manager than going with another solution such as Thycotic."
"The most valuable feature is usability, as it is quite user-friendly."
"The solution is very scalable."
"Its number one feature is discovery. The discovery engine in BeyondTrust is off the charts. When they perform a discovery, you know everything there is about a server, including what software is installed. For example, if you want to group all of your database servers together, you can do that by using discovery and Smart Rules. If a server has Microsoft SQL installed, it gets put into a group based on a Smart Rule. It makes it very easy to determine what is what in your environment. As organizations grow or acquire other companies and merge, they lose track of what they have. BeyondTrust can help you throw a rope around it very rapidly."
"The features I find valuable in Password Safe include password retention and management, session privilege monitoring, live monitoring and recording, and the use of PS automation scripts for creating connections."
"The performance is good."
"The time-saving benefits come from no longer having to remember multiple device passwords."
"It simplifies your compliance and tracking to benchmark other credentials and analytics."
"Overall, I rate BeyondTrust Password Safe as nine out of ten."
"One of the most valuable features is that this is a product designed with enterprises in mind."
"I like the session recording feature. I also like the analytics and reports. You can pull up a report, and the UI is fantastic. The system is recording when nobody's there, so we have a record of what's happening."
 

Cons

"If you add one more layer of security to AWS Secrets Manager, even the programmer will not be able to see the secrets."
"AWS Secrets Manager could support hybrid infrastructure."
"There is a potential improvement in connecting AWS Secrets Manager to Jenkins CI/CD pipeline to automatically reflect changes in production."
"We occasionally have problems with rate limits, although that is a problem more generally with AWS."
"It would be good if the AWS Secrets Manager were more customizable."
"The solution's initial setup process is complicated."
"There is room for improvement in terms of integrating with certain other platforms."
"An area for improvement in AWS Secrets Manager could be expanding integration options beyond AWS services."
"The initial server implementation tasks could be easier to process."
"The pricing is not cheap, but it could be better."
"The effectiveness of BeyondTrust Password Safe's session management capabilities for SSH and RDP is pretty much robust, but it needs more improvement for other applications and web-based applications."
"When we deploy BeyondTrust, we have to deploy our own database on a SQL server. It doesn't deploy the database. I wish BeyondTrust packages the whole solution in one and includes the MySQL database so that when you deploy it, it deploys everything for you. BeyondTrust gives you the software, but you are in charge of setting up your own database. It is a single appliance just for the BeyondTrust portion but not the database. Unless that has changed in later releases, you have to set up your own database for BeyondTrust Password Safe. I find that part complex because we then need the expertise and help of the database team to set it up, which also increases the deployment time. If they can deploy the database, it will reduce the deployment time."
"We'd like to have incremental backups to ensure the solution's information is protected regularly."
"Its documentation can be improved. Its documentation is currently complicated, and it is not good. It needs to be better. Their technical support can also be improved. It is not bad, but it can be better."
"I think that BeyondTrust Password Safe could be improved with more testing. In the beginning, they were practically using customers as beta testers. Maybe the product has evolved since I last used it, but if you look at PAM, privileged access management, whatever's out there has already been done. I don't see there being any other enhancements that are being made regarding PAM, except to support more cloud-based applications."
"There is a limited capacity on the appliance, which I wasn't informed about when I purchased the product. I can have a maximum of 150 rules per appliance; any more than that and rule processing becomes very complex, especially regarding password revision. Hitting a capacity limit you don't know about can be problematic. Ideally, we would not have a limited capacity, allowing us to be in a completely managed state with password rotation for every service account, not just the highly privileged ones."
 

Pricing and Cost Advice

"The cost is somewhat high."
"We purchase a monthly license for the product."
"We've observed that AWS Secrets Manager pricing is based on a per-secret-per-month model. As a result, we prefer to divide our secrets into individual pieces to increase security and grant specific access permissions to certain secrets, systems, or individuals. However, this approach results in higher costs. Therefore, we have been exploring ways to combine our secrets into groups to reduce expenses and simplify management. Nonetheless, we acknowledge that this issue may not be related to the secret manager's functionality."
"I don't believe there is a license cost for the solution."
"The solution is expensive."
"The pricing of BeyondTrust is very good as compared to other products. That was the main reason we decided to go with BeyondTrust at first."
"We just pay for Password Safe. Session management is included, but we don't use it. There aren't any additional costs besides the standard licensing fees. We pay for an annual license."
"When you buy Password Safe and perform your initial Discovery, you have all these servers that are added to your assets in BeyondTrust, but you're not using a license until you actually start managing the systems. BeyondTrust's licensing is based on the systems when they're managed, which means when an administrator is able to connect to the server through BeyondTrust with a managed account. There would be a privileged account on the endpoint when the licensing starts. A significant advantage to that is that there are many organizations that want to evaluate their environment prior to automatic management."
"The product is quite affordable."
"The pricing structure is better than the competitors. It's much cheaper than CyberArk. They do the licensing on the basis of assets, not on the number of users. For CyberArk, they base the licensing on the number of users, and they have an expensive model of pricing. BeyondTrust has a cheaper model."
"It has subscription-based licensing. BeyondTrust is three times less expensive than CyberArk."
"I would rate the pricing a seven out of ten, where one is cheap and ten is expensive."
"At the time, BeyondTrust was significantly cheaper than CyberArk. Pricing-wise, if I remember correctly, it goes by assets. The pricing was negotiated for our instances based on the number of assets that we onboard into the system. It is a little different from CyberArk, where the pricing is by users. So, it depends. If you have a lot of assets, it can get very expensive."
report
Use our free recommendation engine to learn which Enterprise Password Managers solutions are best for your needs.
867,370 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
13%
Manufacturing Company
8%
Government
6%
Financial Services Firm
16%
Computer Software Company
13%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business7
Large Enterprise8
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise5
Large Enterprise10
 

Questions from the Community

Which is better - Azure Key Vault or AWS Secrets Manager?
Azure Key Vault is a SaaS solution. You can easily store passwords and secrets securely and encrypt them. Azure Key Vault is a great solution to ensure you are compliant with security and governanc...
Which is better - HashiCorp Vault or AWS Secrets Manager?
HashiCorp Vault was designed with your needs in mind. One of the features that makes this evident is its ability to work as both a cloud-agnostic and a multi-cloud solution. As a cloud-agnostic sol...
What do you like most about AWS Secrets Manager?
The most valuable feature of AWS Secrets Manager is its seamless integration with various AWS services.
What is your experience regarding pricing and costs for BeyondTrust Password Safe?
My experience with BeyondTrust Password Safe's pricing, setup cost, and licensing has been positive, primarily due to its asset-based licensing model. This is a significant advantage for us because...
What needs improvement with BeyondTrust Password Safe?
We do not utilize the dynamic privilege elevation and delegation feature yet, because the customer is not planning to use this feature. They want to control the manner of user creation processes in...
What is your primary use case for BeyondTrust Password Safe?
Currently, we have one customer using BeyondTrust Password Safe. BeyondTrust Password Safe is usually used for two things: compliance and audit.
 

Also Known As

No data available
BeyondTrust PowerBroker Password Safe
 

Overview

 

Sample Customers

Autodesk, Clevy, Stackery
Aera Energy LLC, Care New England, James Madison University
Find out what your peers are saying about AWS Secrets Manager vs. BeyondTrust Password Safe and other solutions. Updated: July 2025.
867,370 professionals have used our research since 2012.