

CyberArk Privileged Access Manager and HashiCorp Vault compete in privileged access management and secrets management. CyberArk may have an advantage due to its modular, feature-rich design appealing to enterprises with complex needs.
Features: CyberArk Privileged Access Manager provides Central Policy Manager, Privileged Session Manager, and Enterprise Password Vault, facilitating modular integrations and scalability for managing, protecting, and monitoring privileged access. HashiCorp Vault emphasizes secrets management with dynamic secrets and leasing, supporting API integration suited for DevOps and cloud-agnostic environments.
Room for Improvement: CyberArk could improve user experience, session recording search, better documentation, and user training. Meanwhile, HashiCorp Vault users require enhanced cloud integration documentation and a more intuitive initial setup process.
Ease of Deployment and Customer Service: CyberArk supports on-premises, private, and hybrid clouds targeting large enterprises with complex deployments, offering costly yet comprehensive support. HashiCorp Vault, offering an open-source version, suits those with cloud deployments needing fewer resources but may lack the structured support that CyberArk provides.
Pricing and ROI: CyberArk is often expensive, with additional fees for certain features but offers significant ROI in security and risk reduction. HashiCorp Vault's open-source option offers cost savings, with enterprise features scaling in cost but providing reasonable pricing for advanced features, making it a sustainable option for long-term investments with potentially lower upfront costs.
The return on investment lies in improved security infrastructure, addressing over-privileged access, and reducing the risk of credential compromise, which is a major source of data breaches.
The end users have the authority to reconcile the password or verify it before using session isolation, which is one of the unique features that can be enabled through Privileged Session Manager, preventing any attacks from happening within the organization when connected with sessions through CyberArk Privileged Access Manager.
CyberArk Privileged Access Manager has helped customers save on costs primarily by reducing the number of engineering and information security personnel.
HashiCorp Vault is good for maintaining secrets, credentials, and certificates without any complexity.
It increased our security score and made many of our applications follow a standard security compliance.
I have seen a return on investment regarding time saved for the APK signing because the main issue we faced was we were looking for a solution that standardizes it within one repository and allows us to generate different APK artifacts from the same repository.
CyberArk has been exceptional in coming back to us with immediate responses.
It could be forever until you talk to someone who knows what they are doing.
Based on the issue resolution and support quality, I rate the support 10 out of 10.
The customer support for HashiCorp Vault is very good, and its documentation is also very good; the documentation for other HashiCorp tools as well is very good, so I have no complaints.
Their support is quite responsive and they are focused on solving any issues that we are facing.
The CPM can reportedly handle up to 50,000 accounts independently without issue.
I would rate it a ten out of ten for scalability.
They had 40,000 passwords in this one safe, and it was saving the last ten iterations of each password object. That means they had 400,000 password objects in this safe. They exceeded the limit.
If ten colleagues out of ten have access to HashiCorp Vault, we can use it in parallel with no downtime and high productivity, reflecting its scalability.
HashiCorp Vault has more scalability because we vault secrets more efficiently and with more reliability.
You could run it on a cluster which you have numerous machines which are large sizes, making it as big as you want or as small as you want.
Proper fine-tuning and expertise ensure the product performs well.
Overall, the stability of the solution is high.
It has a large customer base and positive feedback within my network.
HashiCorp Vault is a highly stable solution.
HashiCorp Vault has proven stable in my experience, showing no downtime or reliability issues.
The performance issues I experienced were not a HashiCorp Vault issue; it was an issue with a team that was not using it properly.
They want everything to be on the cloud, but even in the SaaS version of CyberArk Privileged Access Manager, they need to deploy some servers on-premises.
We cannot generate a plug-in for web-based applications.
If they want clients to move to the cloud, they need to support them in real-time.
A search function would make it easier for teams to locate and manage their secrets in HashiCorp Vault.
There should be an inbuilt option for automatic initialization rather than running it manually.
It requires other solutions for monitoring as users need to rely on tools that constantly monitor the system, especially database activity.
CyberArk is expensive compared to other products I know.
CyberArk is comparatively expensive compared to other PAM solutions, such as Delinea, especially during renewal.
CyberArk's SaaS solution is particularly expensive.
We did not feel any hidden costs inside this HashiCorp Vault component.
The advantage with Vault is that it is cloud agnostic.
The pricing setup cost for HashiCorp Vault is quite expensive, especially if you consider it against native, cloud-native equivalent tooling.
CyberArk Privileged Access Manager helps ensure data privacy because we now know who is using which credentials and at what time.
It keeps a record of activities, allowing me to easily fetch screen recordings to detect any misuse and see who did what and what happened.
It can integrate with Splunk, SNMP, and other solutions and technologies.
Vault keeps my secrets safe and encrypted.
HashiCorp Vault is used to perform secret rotation automatically, which has made the work significantly easier.
HashiCorp Vault has positively impacted my organization by streamlining access and secret management.
| Product | Market Share (%) |
|---|---|
| CyberArk Privileged Access Manager | 6.9% |
| HashiCorp Vault | 7.7% |
| Other | 85.4% |

| Company Size | Count |
|---|---|
| Small Business | 59 |
| Midsize Enterprise | 40 |
| Large Enterprise | 173 |
| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 4 |
| Large Enterprise | 16 |
CyberArk Privileged Access Manager is a next-generation solution that allows users to secure both their applications and their confidential corporate information. It is extremely flexible and can be implemented across a variety of environments. This program runs with equal efficiency in a fully cloud-based, hybrid, or on-premises environment. Users can now protect their critical infrastructure and access it in any way that best meets their needs.
CyberArk Privileged Access Manager possesses a simplified and unified user interface. Users are able to manage the solution from one place. The UI allows users to view and manage all of the information and controls that administrators need to be able to easily access. Very often, management UIs do not have all of the controls and information streamlined in a single location. This platform provides a level of visibility that ensures users will be able to view all of their system’s most critical information at any time that they wish.
Benefits of CyberArk Privileged Access Manager
Some of CyberArk Privileged Access Manager’s benefits include:
Reviews from Real Users
CyberArk Privileged Access Manager’s software stands out among its competitors for one very fundamental reason. CyberArk Privileged Access Manager is an all-in-one solution. Users are given the ability to accomplish with a single platform what might usually only be accomplished with multiple solutions.
PeerSpot users note the truly all-in-one nature of this solution. Mateusz K., IT Manager at a financial services firm, wrote, "It improves security in our company. We have more than 10,000 accounts that we manage in CyberArk. We use these accounts for SQLs, Windows Server, and Unix. Therefore, keeping these passwords up-to-date in another solution or software would be impossible. Now, we have some sort of a platform to manage passwords, distribute the inflow, and manage IT teams as well as making regular changes to it according to the internal security policies in our bank."
Hichem T.-B., CDO & Co-Founder at ELYTIK, noted that “This is a complete solution that can detect cyber attacks well. I have found the proxy features most valuable for fast password web access.”
HashiCorp Vault is a cloud-agnostic solution used for security and secret management. Its valuable features include integration with other HashiCorp tools, token sharing, open source nature, cloud agnosticism, and on-the-fly encryption management.
The solution provides encryption of data at rest, in use, in transit, on the fly, and linked with applications. It is free to use, and the interface is simple to navigate. HashiCorp Vault has helped organizations with its multiple authentication methods and RESTful API.
HashiCorp Vault Features
Reviews from Real Users
“The greatest benefit of HashiCorp is its ability to manage encryption on the fly. It provides encryption of data at rest, in use, in transit, on the fly, and linked with applications, which was really attractive. The lifecycle of a key is so easy to manage in terms of rotating, revoking, and issuing. They have different auth methods, and I tried all different auth methods. It is seamless.”- Project Manager at a comms service provider.
“The most valuable feature of HashiCorp Vault is that it's an open source solution. Second, it's cloud-agnostic, so it's very easy to maintain and control, which is why we prefer HashiCorp. “ - Mohamed A., Lead DevOps Engineer at Etisalat.
We monitor all Enterprise Password Managers reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.