Overview

Product video
Akeyless Identity Security Platform
Akeyless secures AI agents, machines, and human identities across hybrid and multi-cloud environments. The platform provides a unified control plane for access, credentials, and identity lifecycle - eliminating reliance on long-lived secrets while enforcing least-privilege access and real-time governance.
Built on AWS and powered by patented Distributed Fragments Cryptography (DFC) with a zero-knowledge architecture, Akeyless ensures encryption keys and secrets are never fully assembled or accessible - even to Akeyless. The platform is FIPS 140-3 validated and designed to protect sensitive material from current and post-quantum threats.
Platform Capabilities
-
Secrets Management - Centrally manage, rotate, and automate the entire secrets lifecycle. Move from static credentials to secretless runtime access with ephemeral identities and zero standing privileges.
-
AI Agent Identity Security - Secure autonomous AI agents with ephemeral, scoped access instead of embedding credentials in code, prompts, or workflows. The platform enforces intent-aware control by evaluating requested actions before granting access, issuing task-scoped short-lived credentials, and continuously inspecting execution.
-
Multi-Vault Governance - Unify visibility and policy control across AWS Secrets Manager and third-party vaults from a single pane of glass.
-
Privileged Access Management (PAM) - Enforce just-in-time, least-privilege access with granular role-based policies and centralized auditing.
-
Certificate Lifecycle Management - Automate certificate issuance, renewal, and rotation to eliminate manual processes and prevent outages caused by expired certificates.
-
Enterprise Password Manager - Securely manage and share workforce credentials with strong access controls.
All capabilities operate through a single policy and audit framework, helping eliminate credential sprawl while maintaining consistent governance across every environment.
How Akeyless Secures AI Agents
Instead of static API keys or tokens, AI agents receive policy-bound access only when needed. Every interaction is governed, auditable, and traceable from prompt to outcome. This approach supports MCP-based AI agent workflows and ensures autonomous agents operate within defined security boundaries.
Deep AWS Integration
Akeyless integrates natively with core AWS services to fit into your existing environment:
- Secure Amazon Bedrock AgentCore agents with just-in-time credentials for autonomous AI workloads
- Deploy alongside AWS Secrets Manager for unified multi-vault governance
- Extend Amazon EKS security with Kubernetes secrets injection
- Leverage AWS Key Management Service (KMS) for cryptographic operations and key storage
- Centralize audit logs in Amazon S3 for visibility and compliance
- Integrate with AWS IAM for identity-based authentication
Key Security Differentiators
- Zero-knowledge architecture - Your secrets remain under your control at all times
- Multi-cloud and hybrid extension - Apply a single control plane across AWS, other clouds, and on-premises estates
- Patented DFC technology - Encryption keys are split into fragments that are never combined in a single location
- Identity-based authentication - Replace static credentials with dynamic, identity-driven access
- Granular RBAC and access controls - Define precise policies across users, machines, and AI agents
- Post-quantum cryptography readiness - Protect sensitive material against emerging quantum computing threats
Get Started
A free trial is available directly through AWS Marketplace so you can evaluate the platform in your own environment. For enterprise pricing and Private Offers, contact the Akeyless cloud alliance team through AWS Marketplace. Visit the Pricing tab for details on available plans.
Highlights
- Patented Distributed Fragments Cryptography (DFC) and Zero-Knowledge Architecture: Akeyless uses a unique cryptographic foundation that keeps sensitive material under customer control at all times. The zero-knowledge design means Akeyless never has access to your secrets, and the platform is built to protect against post-quantum threats. FIPS 140-3 validated encryption and multi-cloud KMS support ensure compliance-ready key management across environments.
- AI Agent Identity Security and Secretless Runtime Access: Secure AI agents, machines, and human identities with ephemeral, scoped credentials and just-in-time access. Akeyless enables the transition from static credentials to secretless security through identity-based authentication, zero standing privileges, and intent-aware authorization. Integrations with cloud IAM, Kubernetes, CI/CD, and MCP-based AI agent workflows let teams adopt AI securely without expanding risk.
- Multi-Vault Governance and Unified Platform: Manage secrets, certificates, privileged access, and passwords from a single platform across cloud, on-prem, and hybrid environments. Multi-Vault Governance provides centralized visibility and policy enforcement across AWS and third-party vaults. Granular role-based access controls, centralized auditing, and automated certificate lifecycle management reduce operational complexity and eliminate secrets sprawl.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/12 months |
|---|---|
Clients | $1,000.00 |
Dimensions summary
Top-of-mind questions for buyers
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Akeyless provides 24x7 support with dedicated customer success managers and account managers to help you at every stage of your journey.
Submit a Support Ticket For technical issues, troubleshooting, or general inquiries, submit a ticket at https://www.akeyless.io/submit-a-ticket/
Enterprise Support Enterprise customers can contact cloudalliance@akeyless.io to discuss tailored support options, request private offers, or address account-specific needs.
For questions about refunds or subscription management, please reach out through the support ticket portal or contact your dedicated account manager directly.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Centralized secrets have improved risk control but governance and documentation still need work
What is our primary use case?
The main use case for Akeyless Secrets Management is centralized access control, which is one key aspect that I am looking forward to, but it is still in the gray area. Mostly, we are looking forward to the features of Akeyless Secrets Management, which includes revenue optimization. As Azure Key Vault is a little expensive for us, we are thinking of shifting our infrastructure to some other platform, focusing on risk mitigation, cost reduction, and revenue optimization.
How has it helped my organization?
The security system is good, but as we are in the research phase, we need to dive in a little more to answer how Akeyless Secrets Management has positively impacted our organization.
The ideal risk or the ideal KPI that I am looking forward to that Akeyless Secrets Management can solve is identifying the right issues, such as OT boundaries and the standard privilege ratio, which represents the percentage of static hard-coded credentials versus ephemeral just-in-time tokens used at Level 3.5 DMZ. Target outcomes should ideally be 0% static credentials and 100% dynamic token utilization for telemetry extraction. Additionally, I suggest aiming for a reduced meantime to remediate credential exposure, with cost reduction as the main focus.
What is most valuable?
Akeyless Secrets Management is actually a nice tool because it also integrates zero-knowledge security and it is a JIT access which replaces the standing privileges and hardcoded credentials with identity-based ephemeral secrets generated exclusively at runtime, which is really amazing for us. As we are a global company, it also provides a centralized lifecycle automation, allowing us to orchestrate the creation, rotation, and revocation of both static and dynamic secrets across multiple platforms that we use such as global systems like LN, Fabric, GCP, etc. We can also integrate it with the deployment pipeline.
The best features that Akeyless Secrets Management offers include management boundary security, which is a problem that Akeyless Secrets Management can solve. In terms of different use cases, one is cost reduction, and there is risk elimination and mitigation, particularly in eliminating static credentials at the model perimeter. Another use case involves gateways connecting to Valmet DNA process networks and Valmet industrial network by enforcing JIT ephemeral access tokens, which is one of the best use cases that Akeyless Secrets Management has. We are mostly focusing on the risk mitigation part to integrate Akeyless Secrets Management into Valmet infrastructure.
Currently, we are still in a research phase, and we have not completely used the JIT access token feature, but my research indicates that it can be a great game changer for improving our security at Valmet. JIT access within Valmet security enforces zero-trust boundaries between IT and OT systems by dynamically provisioning least-privileged credentials exclusively for the duration of an authorized telemetry extraction or maintenance task, completely eliminating the attack surface of standard privileges.
Mostly, it is more of automated injection and execution that we are looking forward to. Instantaneous revocation, which occurs upon task completion or lapse of a strict time to live window of 15 minutes, is where the secret platform automatically destroys the token and revokes access to the Valmet endpoint. I see that as a great example for integration with Valmet.
What needs improvement?
Akeyless Secrets Management can be improved by focusing on strategic areas of product enhancements to elevate it from a robust operational tool to a frictionless enterprise standard product. Development must prioritize maturity in release governance, user interface intuitiveness, and developer documentation. Addressing these areas will directly reduce friction and accelerate enterprise-wide adoption.
More documentation should be included in the governance and quality assurance aspects because properly organized documents create a significant impact on the product.
Akeyless Secrets Management could improve its zero-knowledge cryptography capabilities, as the documentation is still lacking. The use of distributed fragments cryptography can be enhanced by splitting encryption key fragments between Valmet's local gateways and Akeyless Secrets Management cloud. This would ensure that the cloud providers maintain mathematically inaccessible telemetry to third parties, presenting a significant improvement in zero-knowledge cryptography.
For how long have I used the solution?
I have been using Akeyless Secrets Management for a couple of weeks.
What do I think about the stability of the solution?
In my experience, Akeyless Secrets Management is stable so far, and I have not found any hard points that I could say are negative. Definitely, it is a great tool.
What do I think about the scalability of the solution?
As a global organization, Akeyless Secrets Management needs to gain trust. Currently, we are still in a testing phase, and I cannot comment directly on scalability, but Akeyless Secrets Management needs to perform well in this regard.
How are customer service and support?
I have not interacted with Akeyless Secrets Management's customer support yet, as it has been an early phase and still in research, so I do not have experience to share.
Which solution did I use previously and why did I switch?
Due to cost considerations, we are switching from Azure to Akeyless Secrets Management, but it is still in the gray area.
How was the initial setup?
We are using a private cloud, as we are a direct gold partner with Microsoft. We have the VDL architecture performed, and we are integrating Akeyless Secrets Management with our VDL, following a hybrid SaaS architecture, which is in a cloud control plane, along with some on-premises API gateways.
What was our ROI?
It is very early to determine a return on investment as we are in the testing phase, but I believe we will see benefits.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, setup cost, and licensing for Akeyless Secrets Management, if the product is excellent, cost usually is not a problem. Most of the time, if the product is nice, the cost can be optimized. I would say it is in a good format and is not much for the service that Akeyless Secrets Management is actually providing.
Which other solutions did I evaluate?
Before choosing Akeyless Secrets Management, we evaluated other options, including Azure Key Vault, which we have been using. Akeyless Secrets Management is the second option we are working on while looking into other players as well.
What other advice do I have?
Akeyless Secrets Management has strong capabilities in risk management and revenue optimization, and it is a great tool worth considering. Currently, the adoption is in the early stage, and there are other players in the key field of secrets management systems such as Azure Key Vault and AWS. Therefore, Akeyless Secrets Management still needs to build trust, but I am looking forward to its growth.
Regarding Akeyless Secrets Management's AI capabilities, it is stable right now and is working on a zero-knowledge sharing infrastructure and model.
Currently, we have not used it on our Valmet data yet, so it is still in the gray area. However, I have read that it is performing better for other users, and once we test it out, I can provide more feedback.
Currently, we are using Microsoft Fabric as our cloud provider.
If you are looking into using Akeyless Secrets Management, I would suggest focusing on their zero-engagement cryptography tool and cost optimization. I would rate Akeyless Secrets Management a six out of ten.
Streamlined PAM with Unified Secrets Management
Centralized secrets management has strengthened security and simplifies credential rotation
What is our primary use case?
Akeyless Secrets Management is used to store secrets such as database credentials and TransUnion certificates for the production environment. For example, a team stores PostgreSQL usernames and passwords in Akeyless instead of in application.properties. A Spring Boot application authenticates to Akeyless at startup, retrieves the credentials at runtime, and uses them to connect to the database. Regarding certificates, a team stores TLS certificates and private keys securely in Akeyless. Application services retrieve them when needed, and administrators can rotate certificates centrally instead of manually replacing them on every server.
How has it helped my organization?
Akeyless Secrets Management has positively impacted our organization because it has improved security through simpler credential rotation policies. Passwords, API keys, and certificates can be updated centrally without manually changing every application. This has resulted in better access control through role-based permissions and enhanced auditability.
Specific outcomes include the reduction in secret rotation time from hours to minutes after automating rotation. Fewer secrets are now stored in source code or configuration repositories after migration to centralized secret management, which is very important for our company. Manual effort has been reduced significantly because of this. New applications' secrets are managed centrally now. Incident response is very fast because speed is everything in this context.
What is most valuable?
Akeyless Secrets Management offers centralized secret management that stores API keys, passwords, certificates, and SSH keys. It provides dynamic and rotated secrets, role-based access control that lets administrators define who or what can access specific secrets, and a zero-knowledge architecture that uses distributed fragments cryptography design. It also offers support for services like Kubernetes.
The feature I rely on the most in my daily work is centralized secret management, as it is often considered the core capability because it reduces the need to store credentials across multiple applications. Role-based access control is also very valuable and important in larger organizations, and because our organization is growing, it is very helpful. Dynamic secret storing is very valuable to me, and Kubernetes support is essential for our operations.
What needs improvement?
Akeyless Secrets Management could be improved in several areas. The initial setup was quite difficult for me. The documentation and tutorials must include end-to-end examples for Kubernetes and CI/CD integrations in general. The UI/UX can be enhanced, and they should offer clear pricing and feature comparisons between different service tiers.
Onboarding and documentation should be clearer for first-time users. Integration examples for different tools, such as integrating Kubernetes and CI/CD pipelines in general, can be improved.
For how long have I used the solution?
I have been using Akeyless Secrets Management for quite some time now in my company.
What do I think about the stability of the solution?
Akeyless Secrets Management is very stable.
What do I think about the scalability of the solution?
Akeyless Secrets Management supports thousands of applications, users, and secrets, which demonstrates that it is highly scalable. It provides support for multi-cloud and hybrid deployments as well.
How are customer service and support?
I do not think we have used customer support for Akeyless Secrets Management, as if used by anyone, it will be the higher authorities in our company. I have not had a single issue with Akeyless Secrets Management.
Which solution did I use previously and why did I switch?
As far as I can remember regarding Akeyless Secrets Management, I do not think we were using anything else before, though it may have been Google Secret Manager before we changed it.
There were other options that the company was looking forward to considering, such as AWS Secrets Manager. We were using Google Secret Manager as far as I can remember a couple of years back, but we chose Akeyless Secrets Management instead.
What was our ROI?
Common metrics regarding return on investment with Akeyless Secrets Management include time saved because of its secret rotation policies. Operational effort has been reduced as it automated credential management. I have hardly seen any security incidents, and overall it has been very beneficial.
What other advice do I have?
The advice that I would personally give regarding Akeyless Secrets Management is that before adopting any secrets management platform, you should define what your security and compliance requirements are. Identify your cloud environments and the DevOps tools that you are integrating with. Evaluate ease of deployment, pricing, rotation policies, access controls, logging, integrations for Kubernetes, and scalability. My overall rating for this product is eight out of ten.