IBM Cloud Secrets Manager

Centrally manage your secrets in a single-tenant, dedicated instance

A vibrant digital scene featuring illuminated cubes arranged on a glowing grid. The setting evokes a futuristic and technological atmosphere, with blue and neon tones dominating the palette. The visuals suggest concepts of data, innovation, and advanced computing.

Manage the lifecycle of secrets

With IBM Cloud® Secrets Manager, you can create secrets dynamically and lease them to applications while you control access from a single location. Powered by HashiCorp Vault, Secrets Manager helps you get the data isolation of a dedicated environment with the benefits of a public cloud.

Which data security service is best for me? Intro to IBM Cloud Secrets Manager
Single Tenancy

Single-tenant data isolation via Vault 

Logging and monitoring

Monitor access and produce audit reports

Protect secrets at rest

Enhance the security of stored secrets with IBM® Key Protect

Secure by default

Built-in, essential security across all IBM Cloud platform and infrastructure services

Learn more
Powered by HashiCorp Vault
  • Get Secure Secret Storage, Data Encryption, PKI
  • Configured with unique Secret Engines and an IAM Auth Engine
  • Built for high availability with seamless failover across three regional data centers
Centralize dynamic and static secrets
  • Manage multiple types of secrets from a single service
  • Create and lease your secrets on demand to control their lifespan
Public Key Infrastructure backed by Hardware Security Module

Create and manage trusted certificates securely using built-in protection

Compliance
  • ISO 27k, SOC, PCI-DSS, GDPR, ISMAP (Japan), C5 (Germany), ENS High (Spain)
  • IBM Cloud Framework for Financial Services
Learn more

Features

Dashboard
- Manage API keys, credentials, certificates and more within one rich UI - Auto rotation and access control
Notifications
Configure with Event Notifications Service to receive secrets life-cycle events
Certificates Management
- Use the imported certificate type to create private keys and CSRs, and manage all your secrets in one secure, dedicated space - SSL, TLS, PKI, public and private - Supported by lets encrypt certificate authority
Secrets groups
Manage access policies at enterprise scale
Locks
Create locks on secrets to prevent them from being deleted or modified while in use
Custom credentials
A customizable set of parameters that define how a secret interacts with a credentials` provider—powered by a Code Engine job implementation

Use Cases

Security posture Secret data isolation Enterprise scale Automated integrations

Related products

Key Protect for IBM Cloud

Monitor and control data encryption keys throughout the key lifecycle, from a single location

Security and Compliance Center Workload Protection

Address unified security, compliance and risk visibility across hybrid multicloud environments

IBM Cloud Kubernetes Service

Deploy secure, highly available clusters in a native Kubernetes experience

Identity and Access Management (AIM) Services

Comprehensive, secure and compliant identity and access management for the modern enterprise

Take the next step

Start at no charge or register for an IBM Cloud account.

Get started for free Register for an account
More ways to explore Cybersecurity Services