Try our new research platform with insights from 80,000+ expert users

CyberArk Secrets Management vs HashiCorp Vault comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CyberArk Secrets Management
Ranking in Enterprise Password Managers
17th
Average Rating
7.2
Reviews Sentiment
6.0
Number of Reviews
5
Ranking in other categories
Access Management (20th)
HashiCorp Vault
Ranking in Enterprise Password Managers
5th
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Featured Reviews

SP
Speedy secret retrieval with monitoring boosts efficiency but documentation needs enhancement
We occasionally experience incidents that delay password injection back into the script. Additionally, we've sometimes focused on vaulting instead of actively managing passwords, which is a concern that requires further exploration. I'm comparing the capabilities of Conjur and Secret Service with our existing products to ensure all our use cases are covered. Some features, like dynamic tokens for Azure and GCP, are already supported by other products but not yet by Conjur. Additionally, full support for GCP Secrets Manager and CyberArk needs confirmation. While Conjur has potential, implementation was complex and required professional services. Simplifying the setup process, particularly for Conjur Edge and Conjur Cloud, would be beneficial. Improving documentation, especially for daily tasks like creating safes, would make the product more user-friendly for those new to Conjur.
Anand-Awasthi - PeerSpot reviewer
Offers dynamic secrets and certificate management for proactive security measures
The best features in HashiCorp Vault are its dynamic certificate management and dynamic secret management, which are the key features that use data effectively. These are very targeted use cases that cut across multiple solutions. I have utilized Vault's encryption capabilities for securing data in transit and at rest, especially for dynamically consuming database encryption, which covers the requirements of various scenarios where databases do not have encryption capability. HashiCorp Vault provides security by rotating the keys and taking all the burden of securing the data from the database. These are key core features that many users employ in this solution. Vault's audit logs provide insights into access patterns and help ensure compliance. These facilities are configurable, and the logs are encrypted, ensuring that anything recorded in the logs is secure. We could use systems that comply with specific standards for audit logging and scanning, especially when working with them. The benefits from HashiCorp Vault include significant advantages in security lifecycle management itself. The value becomes apparent when security incidents occur. It has substantial value in proactively protecting from adverse situations, providing resilience and appreciation by customers in complete security lifecycle management solutions for core infrastructure applications.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"With CyberArk Secrets Management, we were able to resolve the automatic change of the passwords based on timelines. We were also able to retrieve the passwords in an encrypted format by utilizing the CyberArk platform, which was not provided to us by UiPath."
"The audit trails have been extremely important for us in helping our organization meet regulatory requirements."
"CyberArk Secrets Management is a critical solution for strengthening our security posture."
"It's vital for effectively managing and securing my credentials."
"The granular controls of CyberArk Secrets Management are very niche in their development and very secure from the overall secret management perspective, offering high-level functionalities where we have control over user access, which can be tracked and monitored."
"CyberArk's support team is knowledgeable and helpful, consistently responding on time."
"One of the most important features for us is the system's performance, particularly its speed of retrieving secrets."
"The automatic rotation of the password is the top feature."
"The most valuable feature of HashiCorp Vault is version control."
"The benefits from HashiCorp Vault include significant advantages in security lifecycle management itself."
"It is user-friendly and easy to implement from any application point."
"The most valuable feature of HashiCorp Vault is version control."
"It can still be configured by a separate team other than developers. That's why I think it's more secure."
"The feature I find most beneficial in HashiCorp Vault is the secret engine. It integrates smoothly with many applications, making it easy to set up and implement quickly. This allows you to test it easily and see good results rapidly. When you integrate an internal API or application, it quickly manages that application's secrets."
"It is an added value for our customers to have a Secrets Management workflow available that is PaaS/CaaS/KaaS Platform agnostic."
"We were using it because we have compliance requirements around secret management. Having a secure vault and encrypting data was an additional requirement. When we looked at it first, we were just looking for a vault, like a lockbox. The greatest benefit of HashiCorp is its ability to manage encryption on the fly. It provides encryption of data at rest, in use, in transit, on the fly, and linked with applications, which was really attractive."
 

Cons

"Implementation was complex and required professional services."
"We did not have a good experience with technical support because their numerous processes caused delays in engaging, leading to project delays or issues with production."
"The password search feature and integration between different vaults could be enhanced. For instance, when updating passwords in both lower and higher environment vaults, improvement is required in search and upgrade functions."
"We occasionally experience incidents that delay password injection back into the script."
"Implementing it and ensuring seamless password rotations present challenges."
"There is room for improvement with better documentation and less need for CyberArk Secrets Management personnel to assist us with their presence."
"Improvements for CyberArk Secrets Management include enhanced documentation with more use cases and step-by-step integration guides."
"We could use more documentation, primarily to do with integrations."
"There could be a plugin for the database to change the secret automatically. It would be an efficient feature for password security."
"The onboarding is a challenge. It should be more self-service, but it involves reviews and approvals."
"The solution could be much easier to implement."
"An improvement needed is the ability for auto-initialization."
"The technical support was hard to get a hold of and lacking in service."
"An improvement needed is the ability for auto-initialization. There should be an inbuilt option for automatic initialization rather than running it manually."
"In my opinion, HashiCorp Vault could improve its user interface. Right now, they don't offer much in terms of a graphical interface, which means you usually have to manage things manually through API calls. I think CyberArk has a better approach because it provides a UI that integrates features across all its components, making it easier, especially for new users or those from organizations with strict licensing policies."
 

Pricing and Cost Advice

"It is in the middle. It is neither very cheap nor very expensive, so I would place it in the middle."
"CyberArk Secrets Management has a moderate pricing structure based on a per-tenant licensing model rather than a per-user account model like their PAM solution."
"I am using the open-source version of Vault and I would have to buy a license if I want to get support."
"It could do everything we wanted it to do and it is brilliant, but it is super pricey. To be fair to HashiCorp, we drove the price up with our requirements around resiliency. Because of the nature of our company, we don't really operate in the cloud."
"The product is expensive."
"The solution's cost is reasonable."
"The AWS version is much cheaper than HashiCorp Vault."
"In my case, the open-source version works well. It's advisable for small to medium-scale organizations, but for large-scale organizations, you should go with the enterprise version."
report
Use our free recommendation engine to learn which Enterprise Password Managers solutions are best for your needs.
868,706 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Insurance Company
15%
Financial Services Firm
11%
Computer Software Company
9%
Comms Service Provider
8%
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
8%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise4
Large Enterprise9
 

Questions from the Community

What needs improvement with CyberArk Secrets Management?
The tool is very good, but the commercialized training, which is paid, could be improved. Regularizing those trainings as part of a global alliance between the customer, SI partner, and CyberArk wo...
What is your primary use case for CyberArk Secrets Management?
The main use case for CyberArk Secrets Management is application integrations and the CI and CD part. In CyberArk Secrets Management, there are a variety of tools that they cover, one being the Cre...
Which is better - HashiCorp Vault or AWS Secrets Manager?
HashiCorp Vault was designed with your needs in mind. One of the features that makes this evident is its ability to work as both a cloud-agnostic and a multi-cloud solution. As a cloud-agnostic sol...
What do you like most about HashiCorp Vault?
The feature I find most beneficial in HashiCorp Vault is the secret engine. It integrates smoothly with many applications, making it easy to set up and implement quickly. This allows you to test it...
What is your experience regarding pricing and costs for HashiCorp Vault?
If I were to set it up in AWS Secret Management, I would have to manage it, pay, and create secrets without being cloud agnostic. The advantage with Vault is that it is cloud agnostic. I can deploy...
 

Overview

 

Sample Customers

Information Not Available
Adobe, SAP Ariba, Citadel, Spaceflight, Cruise
Find out what your peers are saying about CyberArk Secrets Management vs. HashiCorp Vault and other solutions. Updated: September 2025.
868,706 professionals have used our research since 2012.