No more typing reviews! Try our Samantha, our new voice AI agent.

AWS Secrets Manager vs BeyondTrust Password Safe comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS Secrets Manager
Ranking in Enterprise Password Managers
2nd
Average Rating
9.0
Reviews Sentiment
6.8
Number of Reviews
17
Ranking in other categories
Secrets Management Tools (3rd)
BeyondTrust Password Safe
Ranking in Enterprise Password Managers
10th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
27
Ranking in other categories
Privileged Access Management (PAM) (7th)
 

Mindshare comparison

As of June 2026, in the Enterprise Password Managers category, the mindshare of AWS Secrets Manager is 14.3%, down from 18.0% compared to the previous year. The mindshare of BeyondTrust Password Safe is 2.9%, down from 3.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Enterprise Password Managers Mindshare Distribution
ProductMindshare (%)
AWS Secrets Manager14.3%
BeyondTrust Password Safe2.9%
Other82.8%
Enterprise Password Managers
 

Featured Reviews

Mahadev Metre - PeerSpot reviewer
DevOps Engineer at Paydoh
Consistent security and efficiency improvements optimize IT infrastructure with effective management
When creating AWS Secrets Manager, it should be automated using tools such as Terraform, Puppet, or Ansible. With Terraform code, you specify the encryption key, secret name, rotation policy, and secret replication. Human error occurs when feeding secret values manually, especially with large amounts of secrets to input. Secrets should never be protected only by IAM. They should be protected by multiple layers, such as IAM and one or two KMS keys. Additional security measures could be beneficial if necessary. The rotation policy is crucial because some secrets may become obsolete, require updates, or get compromised. With a weekly rotation policy, if unauthorized access occurs, the exposure is limited to seven days. The rotation policy can be customized according to needs.
PawanShirose - PeerSpot reviewer
Associate Security Consultant at CyberSec Consulting
Has enabled bulk onboarding and password rotation while ensuring secure privilege management
I have faced stability issues when upgrading BeyondTrust Password Safe solution. The upgrade process can be lengthy compared to other modules. For example, upgrading the appliance and reconfiguring HA is easier in PRA. However, in BeyondTrust Password Safe, the upgrade activity can take longer, and I have occasionally experienced being stuck during appliance version upgrades, sometimes duplicating the upgrade. Regarding additional features, we have good features in BeyondTrust Password Safe compared to other modules, such as Secret Safe to secure secrets and the check-in, check-out functionality. We already have the main features, but I think it would be helpful if BeyondTrust implemented a heartbeat check feature on the privileged account level. This feature would allow PAM to check the credentials of privileged accounts, indicating if they are correct or not, showing if the heartbeat has failed if they are wrong.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product is easy to use and is inexpensive."
"I would highly recommend AWS Secrets Manager for secret management in AWS."
"The most valuable feature is the management of credentials."
"The most valuable feature is usability, as it is quite user-friendly."
"It's highly scalable, so I'd rate it a ten out of ten."
"I would recommend everyone to use AWS Secrets Manager for their security and for storing their passwords, because I see that passwords nowadays are easily compromised."
"The most valuable feature of AWS Secrets Manager is the ability to keep data secret and assign access permissions to people to grant or restrict access."
"Integrating with other services was straightforward, especially within the AWS environment."
"BeyondTrust Password Safe is a good PAM tool."
"The technical support and customer services are phenomenal."
"I rate BeyondTrust Password Safe as an overall 10 out of 10."
"It reduces a lot of risks of cyber attacks, malware, and ransomware."
"Screen recording is valuable, and integration with applications is easy. We can customize whatever we want. We did a lot of application integration using scripting."
"One of the most valuable features is that this is a product designed with enterprises in mind."
"BeyondTrust is three times less expensive than CyberArk."
"The features I find valuable in Password Safe include password retention and management, session privilege monitoring, live monitoring and recording, and the use of PS automation scripts for creating connections."
 

Cons

"An area for improvement in AWS Secrets Manager could be expanding integration options beyond AWS services."
"There is a need for better environmental implementation, such as having a security fund as a solution."
"It would be good if the AWS Secrets Manager were more customizable."
"We occasionally have problems with rate limits, although that is a problem more generally with AWS."
"AWS Secrets Manager could support hybrid infrastructure."
"The price of the solution could improve."
"If you don't have enterprise support, then you will not be able to get through to them to get the help. It is not only applicable to AWS Secrets Manager. It is also applicable to any service on AWS."
"The sidecar feature has room for improvement."
"It is a complex product that has a lot of capabilities and does take some learning."
"Named accounts don't work well in this solution. If you use named accounts for your administrative access, the way Smart Rules work is that it takes your SAM account name and matches it to the account name of your privileged ID, which creates limitations on size and how big those names can be because the directory has a 20-character limit."
"We didn't see a return on our investment."
"If they can create a single platform to create a connector, it would be better than using the RBS server."
"The product needs to have better integration with SAP products."
"Adding user behavior analysis to the server or messaging would be beneficial."
"If there was one thing, it would be having the documentation standardized."
"The database instance onboarding should be simplified. The problem is that you can scan the assets and databases inside a server, but you cannot onboard them or manage them with the smart tools. It has to be done manually. I think they should try to include more custom platforms."
 

Pricing and Cost Advice

"The cost is somewhat high."
"I don't believe there is a license cost for the solution."
"The solution is expensive."
"We purchase a monthly license for the product."
"We've observed that AWS Secrets Manager pricing is based on a per-secret-per-month model. As a result, we prefer to divide our secrets into individual pieces to increase security and grant specific access permissions to certain secrets, systems, or individuals. However, this approach results in higher costs. Therefore, we have been exploring ways to combine our secrets into groups to reduce expenses and simplify management. Nonetheless, we acknowledge that this issue may not be related to the secret manager's functionality."
"The pricing of BeyondTrust is very good as compared to other products. That was the main reason we decided to go with BeyondTrust at first."
"The pricing structure is better than the competitors. It's much cheaper than CyberArk. They do the licensing on the basis of assets, not on the number of users. For CyberArk, they base the licensing on the number of users, and they have an expensive model of pricing. BeyondTrust has a cheaper model."
"The product is quite affordable."
"I would rate the pricing a seven out of ten, where one is cheap and ten is expensive."
"When you buy Password Safe and perform your initial Discovery, you have all these servers that are added to your assets in BeyondTrust, but you're not using a license until you actually start managing the systems. BeyondTrust's licensing is based on the systems when they're managed, which means when an administrator is able to connect to the server through BeyondTrust with a managed account. There would be a privileged account on the endpoint when the licensing starts. A significant advantage to that is that there are many organizations that want to evaluate their environment prior to automatic management."
"This solution is not cheap—it's a very expensive solution. Very, very expensive compared to the features and functions that they offer."
"At the time, BeyondTrust was significantly cheaper than CyberArk. Pricing-wise, if I remember correctly, it goes by assets. The pricing was negotiated for our instances based on the number of assets that we onboard into the system. It is a little different from CyberArk, where the pricing is by users. So, it depends. If you have a lot of assets, it can get very expensive."
"We just pay for Password Safe. Session management is included, but we don't use it. There aren't any additional costs besides the standard licensing fees. We pay for an annual license."
report
Use our free recommendation engine to learn which Enterprise Password Managers solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
9%
Manufacturing Company
8%
Comms Service Provider
7%
Financial Services Firm
27%
Manufacturing Company
8%
Healthcare Company
6%
Computer Software Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Large Enterprise10
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise5
Large Enterprise10
 

Questions from the Community

Which is better - Azure Key Vault or AWS Secrets Manager?
Azure Key Vault is a SaaS solution. You can easily store passwords and secrets securely and encrypt them. Azure Key Vault is a great solution to ensure you are compliant with security and governanc...
Which is better - HashiCorp Vault or AWS Secrets Manager?
HashiCorp Vault was designed with your needs in mind. One of the features that makes this evident is its ability to work as both a cloud-agnostic and a multi-cloud solution. As a cloud-agnostic sol...
What needs improvement with AWS Secrets Manager?
AWS Secrets Manager could not be better because there has been no frustration with the product.
What is your experience regarding pricing and costs for BeyondTrust Password Safe?
My experience with BeyondTrust Password Safe's pricing, setup cost, and licensing has been positive, primarily due to its asset-based licensing model. This is a significant advantage for us because...
What needs improvement with BeyondTrust Password Safe?
I have faced stability issues when upgrading BeyondTrust Password Safe solution. The upgrade process can be lengthy compared to other modules. For example, upgrading the appliance and reconfiguring...
What is your primary use case for BeyondTrust Password Safe?
I am working on both BeyondTrust Password Safe and the PRA (Privileged Remote Access). I have three years plus experience working with BeyondTrust Password Safe solution, and I have hands-on, good ...
 

Also Known As

No data available
BeyondTrust PowerBroker Password Safe
 

Overview

 

Sample Customers

Autodesk, Clevy, Stackery
Aera Energy LLC, Care New England, James Madison University
Find out what your peers are saying about AWS Secrets Manager vs. BeyondTrust Password Safe and other solutions. Updated: June 2026.
900,644 professionals have used our research since 2012.