CyberArk is privileged access management for people: it vaults the passwords administrators use, rotates them, and records their sessions. HashiCorp Vault is secrets management for software: applications authenticate to it and receive credentials, often created on demand and set to expire.
CyberArk is now sold as Idira by Palo Alto Networks, and Vault as IBM Vault. Many organizations run both, one for people and one for machines.
- CyberArk vaults and rotates the passwords people use, and records sessions
- Vault creates secrets for applications, with leases that expire
- Session recording is CyberArk PSM; on the HashiCorp side it is Boundary
- Vault is source-available under the Business Source License, not open source
- Vault publishes cloud prices; CyberArk, now Idira, publishes none
On this page
- Two products that answer different questions
- What CyberArk, now Idira, actually is
- What HashiCorp Vault, now IBM Vault, actually is
- Where the two genuinely differ
- What each costs, and what is published
- Using both, which is common
- Choosing, by who owns it and what the auditor asks
- Where people go wrong
- Comparison
- FAQ
The framingTwo products that answer different questions
The CyberArk vs HashiCorp Vault comparison goes wrong when it starts from the word vault, which both vendors use for different things.
CyberArk starts from the human administrator. A person needs to log in to a domain controller, a firewall or a production database with an account that can change anything. The privileged access management question is how that person gets the credential without ever knowing it, how their session is watched, and how the password changes the moment they are done.
HashiCorp Vault starts from the workload. An application, a container or a CI/CD pipeline needs a database password, an API key or a certificate to do its job. The secrets management question is how that software proves who it is and receives only the secret it is entitled to, ideally one that stops working shortly afterwards.
Each vendor has spent a decade reaching into the other's territory. CyberArk built a secrets product for applications, and HashiCorp's own documentation now describes Vault as providing "privileged access and secret management". But the starting point still shows in the architecture, in what each product does well, and in how each one is priced.
CyberArkWhat CyberArk, now Idira, actually is
Palo Alto Networks completed its acquisition of CyberArk on February 11, 2026, and on May 12, 2026 introduced Idira, which it describes as the next-generation identity security platform built on CyberArk's legacy.
The old product pages on cyberark.com now redirect to Palo Alto Networks, and the product documentation is branded Idira Docs. The press release on the acquisition says the CyberArk solutions continue to be available as a standalone platform, so existing deployments carry on under the new name.
The privileged access manager, in its self-hosted form, is built from a handful of components with long-standing names:
- The Digital Vault, the storage engine, installed on a dedicated server for complete data isolation. It holds the privileged passwords and SSH keys in containers called Safes.
- The Central Policy Manager (CPM), which changes passwords on remote machines automatically, with no human involved, according to policy, and stores the new value back in the vault. It also verifies and reconciles passwords that drifted.
- The Privileged Session Manager (PSM), which brokers the session itself. The user connects through it without seeing the password, and PSM can record everything that happens, with DVR-like playback, stored in the vault for auditors.
- The web interface (PVWA), where people request, approve and use access.
The same capabilities are sold as a SaaS service. For applications there is a separate Secrets Manager, offered as SaaS or self-hosted, and grown from the Conjur product, whose open source server is still published under the GNU Lesser General Public License.
A newer service, Secrets Hub, connects to AWS Secrets Manager, Azure Key Vault, Google Secret Manager and HashiCorp Vault through their native APIs, so that the security team can govern secrets that developers keep elsewhere, with no migration.
VaultWhat HashiCorp Vault, now IBM Vault, actually is
IBM completed its acquisition of HashiCorp on February 27, 2025. The Vault pricing page now names the products IBM Vault, IBM HCP Vault Dedicated for the managed cloud service, and IBM Vault Enterprise for self-managed deployments.
Vault is an API-driven service that applications authenticate to. Its core ideas are a little different from a password vault:
Dynamic secrets and leases. Instead of storing a database password and handing it out, Vault can create a new credential when an application asks for one. Every dynamic secret comes with a lease, a time to live after which it stops working unless renewed.
When a lease is revoked, the secret is invalidated immediately; with the AWS secrets engine, in the documentation's own example, the access keys are deleted from AWS the moment the lease is revoked. A credential that leaks from a log file is worth very little if it expired an hour ago.
Secrets engines. Each type of secret is handled by a plugin: key-value storage for static secrets, database and cloud credential engines, a PKI engine that acts as a certificate authority, and a transit engine that performs encryption as a service, so applications can encrypt data without ever holding the key.
Seal and unseal. A Vault server starts sealed: it can read its storage but cannot decrypt anything in it.
Unsealing traditionally needs a threshold of key shares produced with Shamir's Secret Sharing, held by different people, or it can be delegated to a cloud KMS or a hardware security module. HashiCorp recommends its integrated Raft storage for most deployments rather than an external database.
The license changed, and it matters. Vault's source code is published, but under the Business Source License 1.1, with IBM as licensor. Production use is allowed unless you offer Vault to third parties as a hosted or embedded service that competes with IBM's paid versions, and each release converts to the open source MPL 2.0 four years after publication.
Most comparison articles still call Vault open source; for anyone building a product on top of it, that difference is the first thing to check.
The differencesWhere the two genuinely differ
Static against dynamic. CyberArk's classic model is a real account with a real password that exists on the target system, kept in the vault and rotated by the CPM on a schedule or after each use.
Vault's strongest model is a credential that did not exist until the application asked for it and will not exist shortly after. Idira now also sells zero standing privileges, ephemeral access to cloud consoles and infrastructure, which moves it toward Vault's end for people. Both approaches remove standing, shared passwords; they start from opposite ends.
Session recording. Recording what an administrator did on a server is a core PAM function and a regular audit requirement. In CyberArk it is PSM.
Vault on its own does not record sessions: HashiCorp's product for brokered, recorded sessions is Boundary, an identity-aware proxy, and session recording is in the Plus editions of Boundary, not in Vault. If an auditor asks to see what was typed on the payroll database server last Tuesday, that requirement points at PAM.
The audit trail. Both products produce the records that security and compliance reviews ask for, and they record different things. Vault's audit devices record every API request and response, writing a keyed HMAC-SHA256 hash in place of most sensitive values, so the trail shows which application or user read which secret, and when.
CyberArk records who requested which privileged credential and, through PSM, the session itself, so the trail shows what the person did with the access. The control your auditors test decides which of the two records you need.
People against pipelines. CyberArk's workflows assume a person in the loop: request, approval, a brokered login. Vault's assume none: an application authenticates with its platform identity, a Kubernetes service account or a cloud role, and receives a secret in milliseconds, thousands of times an hour.
Using either one for the other's job works, and it is where the friction comes from.
Deployment. The self-hosted CyberArk vault is a hardened, dedicated Windows server with a disaster recovery replica. Vault is a cluster of nodes that replicate over Raft, run anywhere, and are usually automated with infrastructure as code. The operating skill sets are different, and so are the teams that tend to own each one.
PricingWhat each costs, and what is published
Vault publishes prices for its managed cloud service, and CyberArk, under either name, publishes none.
| IBM HCP Vault Dedicated | Per cluster | Per client | A month, before clients |
|---|---|---|---|
| Development | $0.62 an hour | Up to 25 clients | $452.60 |
| Essentials | $1.58 an hour | $73 a month each | $1,153.40 |
| Standard | $1.85 an hour | $73 a month each | $1,350.50 |
Monthly figures use 730 hours in a month. The Development tier is for exploring enterprise features in a limited environment, not for production. On Essentials, a cluster serving 50 clients comes to $1,153.40 plus $3,650, or $4,803.40 a month.
The number that decides a Vault bill is the client count, and the definition is broad. Vault's documentation defines a client as anything that connects and authenticates to Vault to accomplish a task: human users, applications, virtual machines, containers and Kubernetes pods, CI/CD pipelines and Vault agents all count.
Before comparing a quote, count those honestly, because the per-client line will outgrow the per-cluster line quickly.
Self-managed IBM Vault Enterprise comes in Essentials, Standard and Premium editions on custom pricing, with premium support included. CyberArk's privileged access and secrets products, now under Idira, are sold by quote; none of the Idira pages read for this article shows a price.
TogetherUsing both, which is common
Plenty of organizations do not choose. The pattern that appears again and again is CyberArk for the human administrators, because of session recording, approvals and the audit trail, and Vault for applications and pipelines, because of dynamic secrets and the API.
Both vendors now build for that arrangement. Idira's Secrets Hub connects to HashiCorp Vault, without a migration, to discover and govern the secrets kept in it. CyberArk's own Secrets Manager synchronizes Safes from the privileged access vault every minute, so a password the CPM rotates reaches the application that needs it.
An organization that already runs CyberArk PAM has a single-vendor path for application secrets; an organization that already runs Vault can add Boundary for brokered sessions. Neither path is wrong. The mistake is buying the second product for a job the first one already does.
ChoosingChoosing, by who owns it and what the auditor asks
Four questions settle most decisions faster than a feature matrix.
Who will run it? Privileged access management is usually owned by the security team, and its users are administrators, help desk staff and outside vendors who need controlled access to systems.
Secrets management is usually owned by a platform or DevOps team, and its users are mostly not people at all. A tool bought by one team for the other team's problem tends to sit half deployed.
What does the audit or compliance requirement say? If auditors ask who logged in to a system with an administrative account and what that person did, the answer is access control with session recording, and that is the privileged access management side.
If the requirement is that no credential lives in source code, configuration files or CI/CD variables, the answer is secrets management with short-lived credentials.
Are you counting users or workloads? A company with 40 administrators and 3 applications has a privileged access problem. A company with 6 administrators and 400 microservices has a secrets problem. Count both before talking to a vendor; on Vault's published price list, the second number is the one that sets the bill.
What infrastructure is it protecting? Vault is at home in cloud and Kubernetes infrastructure managed as code. CyberArk's privileged access tools were built for the servers, network devices and databases of a traditional data center, and now reach into cloud consoles too.
For a team entirely inside one cloud, the cloud provider's own secret store is a third choice that both vendors are now designed to govern rather than replace.
The free options are real, and limited. Vault's source-available build can be run in production at no license cost within the terms of the Business Source License, and the managed service comes with a $500 trial credit.
CyberArk's open source Conjur server is free under the LGPL. Neither free route includes the session recording, support or management tools that make these products worth their price at scale.
PitfallsWhere people go wrong
Putting application secrets through a PAM workflow. A pipeline that fetches a credential thousands of times a day does not want an approval step or a brokered login. That is why CyberArk built a separate Secrets Manager for applications rather than pointing them at the privileged access workflow.
Treating Vault as privileged access management. Vault stores and rotates secrets well, and it does not record what an administrator did. If session recording is an audit requirement, it needs Boundary or a PAM product.
Losing the unseal keys. With Shamir unsealing, a Vault whose key holders have left the company cannot be unsealed, and its data cannot be read. Decide custody, or use auto-unseal through a KMS or HSM, before production.
Counting Vault clients too narrowly. Every pipeline and every pod that authenticates is a client on the bill. A proof of concept with ten applications can turn into hundreds of clients in production.
Assuming Vault is open source. It is source-available under the Business Source License. That is fine for most internal use and a real constraint for anyone offering it as part of a hosted product.
Comparing old names. Search results still compare CyberArk Conjur with HashiCorp Vault as independent vendors. Both are now inside larger companies, and the product names in a quote will be Idira and IBM.
ComparisonCyberArk and HashiCorp Vault, on the criteria that decide it
| Criterion | CyberArk (Idira) | HashiCorp Vault (IBM) |
|---|---|---|
| Built first for | Human administrators | Applications and pipelines |
| Rotates passwords on real accounts | Yes, the CPM | Yes, auto-rotating secrets |
| Creates short-lived secrets on demand | Ephemeral access, for cloud | Yes, dynamic secrets with leases |
| Records privileged sessions | Yes, PSM | No, needs Boundary |
| Brokers a login without revealing the password | Yes, PSM | With Boundary |
| Encryption as a service | Not on its product pages | Yes, transit engine |
| Built-in certificate authority | Certificate Manager, a separate product | Yes, PKI engine |
| Source code published | Conjur server, LGPL | Whole product, Business Source License |
| Published price | None | Cloud service, per cluster and client |
| Syncs secrets to cloud secret stores | Yes, Secrets Hub | Yes, secrets sync |
The first three rows are the decision. If the requirement is that people never know the passwords they use and that their sessions are recorded, it is CyberArk. If the requirement is that applications receive credentials that expire on their own, it is Vault. If it is both, it is usually both.
FAQFrequently asked questions
Is CyberArk better than HashiCorp Vault?
Neither is better in general, because they start from different jobs. CyberArk is stronger for human administrators: vaulting, rotation and recorded sessions. Vault is stronger for applications: dynamic secrets, leases and an API built for volume.
What is CyberArk called now?
Palo Alto Networks completed its acquisition of CyberArk on February 11, 2026, and introduced the Idira identity security platform on May 12, 2026. CyberArk product pages now redirect to Palo Alto Networks, and the documentation is branded Idira.
What is HashiCorp Vault called now?
IBM completed its acquisition of HashiCorp on February 27, 2025. The pricing page names the products IBM Vault, IBM HCP Vault Dedicated for the managed service and IBM Vault Enterprise for self-managed deployments.
Is HashiCorp Vault open source?
Not anymore. The source is published under the Business Source License 1.1, which allows production use except offering Vault as a competing hosted or embedded service. Each release converts to the open source MPL 2.0 four years after publication.
How much does HashiCorp Vault cost?
The managed HCP Vault Dedicated service starts at $1.58 per cluster per hour on Essentials, plus $73 a month per Vault client, and $1.85 an hour on Standard. A Development tier at $0.62 an hour covers up to 25 clients for evaluation. Self-managed Vault Enterprise is priced by quote.
How much does CyberArk cost?
It is not published. Neither the Idira privileged access pages nor the secrets management pages show a price, so the only route is a quote.
What is a dynamic secret?
A credential Vault creates at the moment an application asks for it, with a lease that sets how long it is valid. When the lease expires or is revoked, the credential stops working; with the AWS engine, the access keys are deleted from AWS.
Does HashiCorp Vault record sessions like CyberArk?
No. Vault manages secrets. HashiCorp's product for brokered access and session recording is Boundary, and session recording is in its Plus editions.
What is the difference between CyberArk Conjur and HashiCorp Vault?
Conjur is CyberArk's secrets management product for applications, now sold as Idira Secrets Manager in SaaS and self-hosted forms, with an open source server under the LGPL. It is the part of CyberArk that competes directly with Vault, and it can synchronize secrets from the CyberArk privileged access vault.
Can CyberArk and HashiCorp Vault work together?
Yes. Idira's Secrets Hub connects to HashiCorp Vault through its API to discover and govern the secrets stored there, without a migration. A common arrangement is CyberArk for administrators and Vault for applications.
What is a Vault client for billing?
Anything that authenticates to Vault to do a task: people, applications, virtual machines, containers, Kubernetes pods, CI/CD pipelines and Vault agents. On HCP Vault Dedicated Essentials and Standard, each one costs $73 a month.
Which should a small company choose?
Usually neither at first. A small team is better served by the secret store its cloud provider already includes and by multi factor authentication on every administrator account. Privileged access management and a dedicated secrets platform start paying for themselves when the number of administrators, systems and pipelines outgrows what people can track.
Keep readingRelated concepts
Read next · Identity and access What Is MFA? The control every administrator account needs before any privileged access product is worth buying. Open this next16 min- Identity and access · 13 min Zero Trust Explained Short-lived secrets and zero standing privileges are this model applied to credentials.
- Cryptography · 11 min Encryption Algorithms, and the Two Families They Fall Into What Vault’s transit engine and every vault’s encryption at rest are built from.
- Identity and access · 10 min IAM vs PAM, and What PAM Looks Like Without a PAM Suite What privileged access management means for a small company, and how much of it needs no suite at all.
- Cloud security · 11 min KMS vs Secrets Manager, and Why Every Secret Already Uses KMS The AWS native way to store and rotate credentials, and how it uses KMS underneath.