What is our primary use case?
The main use case for Akeyless Secrets Management is centralized access control, which is one key aspect that I am looking forward to, but it is still in the gray area. Mostly, we are looking forward to the features of Akeyless Secrets Management, which includes revenue optimization. As Azure Key Vault is a little expensive for us, we are thinking of shifting our infrastructure to some other platform, focusing on risk mitigation, cost reduction, and revenue optimization.
How has it helped my organization?
The security system is good, but as we are in the research phase, we need to dive in a little more to answer how Akeyless Secrets Management has positively impacted our organization.
The ideal risk or the ideal KPI that I am looking forward to that Akeyless Secrets Management can solve is identifying the right issues, such as OT boundaries and the standard privilege ratio, which represents the percentage of static hard-coded credentials versus ephemeral just-in-time tokens used at Level 3.5 DMZ. Target outcomes should ideally be 0% static credentials and 100% dynamic token utilization for telemetry extraction. Additionally, I suggest aiming for a reduced meantime to remediate credential exposure, with cost reduction as the main focus.
What is most valuable?
Akeyless Secrets Management is actually a nice tool because it also integrates zero-knowledge security and it is a JIT access which replaces the standing privileges and hardcoded credentials with identity-based ephemeral secrets generated exclusively at runtime, which is really amazing for us. As we are a global company, it also provides a centralized lifecycle automation, allowing us to orchestrate the creation, rotation, and revocation of both static and dynamic secrets across multiple platforms that we use such as global systems like LN, Fabric, GCP, etc. We can also integrate it with the deployment pipeline.
The best features that Akeyless Secrets Management offers include management boundary security, which is a problem that Akeyless Secrets Management can solve. In terms of different use cases, one is cost reduction, and there is risk elimination and mitigation, particularly in eliminating static credentials at the model perimeter. Another use case involves gateways connecting to Valmet DNA process networks and Valmet industrial network by enforcing JIT ephemeral access tokens, which is one of the best use cases that Akeyless Secrets Management has. We are mostly focusing on the risk mitigation part to integrate Akeyless Secrets Management into Valmet infrastructure.
Currently, we are still in a research phase, and we have not completely used the JIT access token feature, but my research indicates that it can be a great game changer for improving our security at Valmet. JIT access within Valmet security enforces zero-trust boundaries between IT and OT systems by dynamically provisioning least-privileged credentials exclusively for the duration of an authorized telemetry extraction or maintenance task, completely eliminating the attack surface of standard privileges.
Mostly, it is more of automated injection and execution that we are looking forward to. Instantaneous revocation, which occurs upon task completion or lapse of a strict time to live window of 15 minutes, is where the secret platform automatically destroys the token and revokes access to the Valmet endpoint. I see that as a great example for integration with Valmet.
What needs improvement?
Akeyless Secrets Management can be improved by focusing on strategic areas of product enhancements to elevate it from a robust operational tool to a frictionless enterprise standard product. Development must prioritize maturity in release governance, user interface intuitiveness, and developer documentation. Addressing these areas will directly reduce friction and accelerate enterprise-wide adoption.
More documentation should be included in the governance and quality assurance aspects because properly organized documents create a significant impact on the product.
Akeyless Secrets Management could improve its zero-knowledge cryptography capabilities, as the documentation is still lacking. The use of distributed fragments cryptography can be enhanced by splitting encryption key fragments between Valmet's local gateways and Akeyless Secrets Management cloud. This would ensure that the cloud providers maintain mathematically inaccessible telemetry to third parties, presenting a significant improvement in zero-knowledge cryptography.
For how long have I used the solution?
I have been using Akeyless Secrets Management for a couple of weeks.
What do I think about the stability of the solution?
In my experience, Akeyless Secrets Management is stable so far, and I have not found any hard points that I could say are negative. Definitely, it is a great tool.
What do I think about the scalability of the solution?
As a global organization, Akeyless Secrets Management needs to gain trust. Currently, we are still in a testing phase, and I cannot comment directly on scalability, but Akeyless Secrets Management needs to perform well in this regard.
How are customer service and support?
I have not interacted with Akeyless Secrets Management's customer support yet, as it has been an early phase and still in research, so I do not have experience to share.
Which solution did I use previously and why did I switch?
Due to cost considerations, we are switching from Azure to Akeyless Secrets Management, but it is still in the gray area.
How was the initial setup?
We are using a private cloud, as we are a direct gold partner with Microsoft. We have the VDL architecture performed, and we are integrating Akeyless Secrets Management with our VDL, following a hybrid SaaS architecture, which is in a cloud control plane, along with some on-premises API gateways.
What was our ROI?
It is very early to determine a return on investment as we are in the testing phase, but I believe we will see benefits.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup cost, and licensing for Akeyless Secrets Management, if the product is excellent, cost usually is not a problem. Most of the time, if the product is nice, the cost can be optimized. I would say it is in a good format and is not much for the service that Akeyless Secrets Management is actually providing.
Which other solutions did I evaluate?
Before choosing Akeyless Secrets Management, we evaluated other options, including Azure Key Vault, which we have been using. Akeyless Secrets Management is the second option we are working on while looking into other players as well.
What other advice do I have?
Akeyless Secrets Management has strong capabilities in risk management and revenue optimization, and it is a great tool worth considering. Currently, the adoption is in the early stage, and there are other players in the key field of secrets management systems such as Azure Key Vault and AWS. Therefore, Akeyless Secrets Management still needs to build trust, but I am looking forward to its growth.
Regarding Akeyless Secrets Management's AI capabilities, it is stable right now and is working on a zero-knowledge sharing infrastructure and model.
Currently, we have not used it on our Valmet data yet, so it is still in the gray area. However, I have read that it is performing better for other users, and once we test it out, I can provide more feedback.
Currently, we are using Microsoft Fabric as our cloud provider.
If you are looking into using Akeyless Secrets Management, I would suggest focusing on their zero-engagement cryptography tool and cost optimization. I would rate Akeyless Secrets Management a six out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?