IBM Cloud Secrets Manager

Centrally manage your secrets in a single-tenant, dedicated instance

Abstract 3D render of several digital cubes

Overview

Manage the lifecycle of secrets

With IBM Cloud® Secrets Manager, you can create secrets dynamically and lease them to applications while you control access from a single location. Powered by HashiCorp Vault, Secrets Manager helps you get the data isolation of a dedicated environment with the benefits of a public cloud.

Secure secrets storage & protection

Store secrets in a dedicated environment with built-in security controls, encryption, and data isolation to protect sensitive credentials throughout their lifecycle.

Secrets lifecycle management

Manage, generate, lease, rotate, and secure certificates and secrets from a centralized service with integrated PKI capabilities.

Visibility, governance & compliance

Monitor secret access, generate audit reports, and meet regulatory and industry compliance requirements with comprehensive governance controls.

Powered by HashiCorp Vault
  • Get Secure Secret Storage, Data Encryption, PKI
  • Configured with unique Secret Engines and an IAM Auth Engine
  • Built for high availability with seamless failover across three regional data centers

Features

Everything you need to secure and manage secrets at scale

Dashboard
- Manage API keys, credentials, certificates and more within one rich UI - Auto rotation and access control
Notifications
Configure with Event Notifications Service to receive secrets life-cycle events
Certificates Management
- Use the imported certificate type to create private keys and CSRs, and manage all your secrets in one secure, dedicated space - SSL, TLS, PKI, public and private - Supported by lets encrypt certificate authority
Secrets groups
Manage access policies at enterprise scale
Locks
Create locks on secrets to prevent them from being deleted or modified while in use
Custom credentials
A customizable set of parameters that define how a secret interacts with a credentials` provider—powered by a Code Engine job implementation

Use cases

Put secrets management into practice

Maintaining security posture without losing velocity

The shift to cloud-native models aims to boost development speed for application teams. They expect this acceleration without compromising security and rely on their cloud provider to offer solutions that support both.

Solution: Secrets Manager integrates with DevOps tools like IBM Cloud Toolchains to provide security where teams manage secrets. Its secrets group feature and activity tracker ensure proper access control.

An empty data center with several server racks illuminated by blue lights

Maintaining required secret data isolation while building cloud native

  • Global Bank: The CISO mandates that application and user secrets must be stored separately from other enterprise secrets.
  • Healthcare Group: Applications accessing sensitive patient data must ensure the cloud provider cannot access this data with hosted secrets
  • Automotive Manufacturer: After moving workloads to the cloud, the company requires the same data isolation as their previous on-premise Vault instance

Solution: Financial and healthcare institutions with sensitive data, like credit histories or EHR records, have low risk tolerance. They worry about storing access credentials in a vulnerable multi-tenant environment on IBM Cloud. With Secrets Manager, they can use HashiCorp Vault for single-tenant isolation, audit access with Activity Tracker, and protect vault access with their own encryption keys via Key Protect (BYOK).

Focused male IT technician using digital tablet in dark server room

Managing multiple IBM Cloud secret types at enterprise scale

A healthcare group needs to securely manage various secrets in a single-tenant environment. They currently use multiple tools, some of which are multi-tenant, for handling API keys, user credentials, text, and certificates. They lack the time to train teams, switch between applications, and compile audit reports from different sources. They need a streamlined solution for multiple teams and a high volume of instances.

Solution: With Secrets Manager, they can securely manage API keys, user credentials, and text in one centralized service. This allows them to benefit from public cloud while maintaining single tenancy and efficiently administering policies and permissions across the company.

Diverse Multi-Ethnic Team Working in Big City Office

Securely enabling automated communication between microservices

A large bank's cloud security team needs to help development teams securely build automated integrations between consumer lending applications and other micro-services with sensitive information. For example, a lending app needs to access another app to decide on loan approvals. The security team wants to enable this without creating vulnerabilities.

Solution: With Secrets Manager, they can generate IAM API keys, set access policies, and securely embed the API for key retrieval in their app.

Related products

Key Protect for IBM Cloud

Monitor and control data encryption keys throughout the key lifecycle, from a single location

Security and Compliance Center Workload Protection

Address unified security, compliance and risk visibility across hybrid multicloud environments

IBM Cloud Kubernetes Service

Deploy secure, highly available clusters in a native Kubernetes experience

Identity and Access Management (AIM) Services

Comprehensive, secure and compliant identity and access management for the modern enterprise

Take the next step

Start at no charge or register for an IBM Cloud account.

  1. Get started for free
  2. Register for an account