Parameter; Hashicorp; KeyWhiz
Supported types of secrets; SSH keys, TLS keys, Docker credentials, service accounts tokens - OpenShift\Kubernetes\Nomad, login pass pairs, services and API certificates, env variables; TLS certificates/keys, GPG keys, API tokens, database credentials;
Supported types of applications; Cloud - AWS, GCP, Azure, Alibaba Cloud, databases - Oracle, MS SQL, MySQL, CI \ CD - GitLab CI, TeamCity, Container Orchestration - Kubernetes, OpenShift, Swarm, IaaC - Ansible, Terraform, Helm; Cloud - AWS, databases - PostgreSQL, MySQL. CI \ CD - GitLab CI, Jenkins. Container Orchestration - Kubernetes, Swarm,
IaaC - Terraform;
Strong authentication; OAuth, OpenID Connect compatible; OAuth compatible
Dynamic Secrets and Secrets rotation; Yes; Yes
ACL; Yes; Yes
Secrets wrapping for one-time contractors access; Yes; No
Management interfaces; API, CLI, Web; API, CLI
High availability; Yes; No
Logging of access to secrets; Yes, it can't work if there is no audit device enabled; Yes
Tokenisation for sensitive data; Yes; No
Editions; Open Source, Enterprise + Modules; Open Source
Delivery type; On-Premise, IaaS; On-Premise
Availability on cloud marketplaces; AWS, Azure, Google Cloud; No