Static Secrets
OpenBao provides a central store for your credentials – with versioning, lease management, and a full audit log. Secrets no longer need to live in Git repositories or ConfigMaps.
Secrets Management
Made in Germany
ayedo operates OpenBao for your secrets, certificates, and dynamic credentials – central, auditable, and part of your Software Delivery Platform. You use the APIs; operations and availability stay with us.































Manage secrets securely
Our secrets management is based on OpenBao in the platform cluster – central secrets without in-house build-out, predictable instance costs, and developers without vault ops. ayedo handles day-2 including auto-unseal and Kubernetes integration.
Static Secrets
OpenBao provides a central store for your credentials – with versioning, lease management, and a full audit log. Secrets no longer need to live in Git repositories or ConfigMaps.
Dynamic Secrets
Database credentials, cloud IAM roles, and service accounts are created on demand, rotated automatically, and can be revoked at any time.
PKI & Certificates
An internal certificate authority issues certificates for mTLS, service mesh, and ingress – issuance and renewal are fully automated.
Encryption as a Service
The transit engine encrypts sensitive data at rest and in transit – without requiring you to build your own key management infrastructure.
Kubernetes Integration
The External Secrets Operator syncs your secrets into workload clusters – either as Kubernetes secrets or as mounted files.
EU Infrastructure
Your key material and secrets remain on European infrastructure – GDPR-compliant and independent of US cloud providers.
Pricing
Managed OpenBao is available as part of the ayedo platform – in the ayedo Cloud, on a dedicated cluster, or on your own infrastructure (BYOC/on-premises).
HA setup with auto-unseal
Kubernetes secrets sync (ESO)
Audit logging included
OIDC via ayedo ID
Operated in the central Platform Cluster
OpenBao in a dedicated Platform Cluster
Your own, fully isolated instance
Custom namespaces & policies
Disaster recovery between regions
Custom SLAs
Compare with alternatives
Managed OpenBao on the ayedo platform provides sovereign secrets management on European infrastructure – cloud-agnostic and independent of any single cloud provider.
| Criterion | ayedo | AWS Secrets Manager |
|---|---|---|
| Jurisdiction | EU / GDPR-compliant | US / Cloud Act |
| Multi-cloud | Cloud-agnostic | AWS-only |
| Dynamic secrets | OpenBao engines | Limited |
| PKI | Built-in | ACM separate |
| Criterion | ayedo | Azure Key Vault |
|---|---|---|
| Vendor lock-in | Open ecosystem | Azure-focused |
| Kubernetes | Native operator / ESO | Azure-specific |
| On-premises / BYOC | Available | Cloud-first |
| Support | Personal, in German/English | Ticket system |
| Criterion | ayedo | GCP Secret Manager |
|---|---|---|
| Jurisdiction | EU hosting | US company |
| Encryption | Transit + KMS | Cloud KMS |
| Audit | Full audit log | Cloud Logging |
| Pricing transparency | Fixed per instance | Per secret/op |
The ayedo Cloud is ISO 27001-certified and meets the requirements of current EU regulations by default: GDPR, NIS-2, DORA, CRA, Data Act and the Cloud Sovereignty Framework.
GDPR-compliant data processing
EU data residency (Germany), customer-managed keys (BYOK/BYOHSM), encryption at rest/in transit. ISO 27001-certified data protection management. More about GDPR.
NIS-2-compliant operations
24/7 monitoring, incident response, BCP/DR processes, supply chain transparency (SBOM). More about NIS-2.
DORA-ready
ICT risk management, documented exit strategies, third-party risk management, TLPT readiness. More about DORA.
CRA-compliant software supply chain
SBOM generation, CVE scanning, signed container images, GitOps-based audit trails. More about the CRA.
Cloud Sovereignty Framework
EU-based operations, open standards, exit capability without lock-in. More about the framework.
Data Act-compliant portability
Open APIs, standardized formats, complete exit runbooks. More about the Data Act.
Integrated compliance roadmap
How ayedo systematically addresses GDPR, NIS-2, DORA, CRA, Data Act and ISO 27001/9001. To the overview.
Part of the Software Delivery Platform
OpenBao is a core pillar for Identity, Code Repository, Delivery, and all Managed Apps – because secrets do not belong in Git repositories.
Identity
Access to OpenBao is provided via ayedo ID or your dedicated Keycloak – without additional local user accounts.
Managed Kubernetes
Your secrets are synced automatically into your workload clusters – no manual copying required.
Delivery
Argo CD pulls secrets directly from OpenBao – so no credentials end up in your Git repositories.
OpenBao App
You can find the technical specification and block reference on the OpenBao managed app page.
Excellent performance and maximum uptime - that's what we wake up for. And sometimes even in the middle of the night.
100+ clusters
We operate more than 100 Kubernetes clusters in production for our customers.
300+ databases
We operate, monitor, and protect more than 300 production databases.
1 Petabyte Object-Storage
We operate one petabyte of object storage for backups, artifacts, and application data.
100 million timeseries
Our monitoring systems ingest 4 million datapoints per second.
38.000+ Logs
Our collectors capture logs continuously and store them GDPR-compliant — over 100 billion entries per month.
5.000+ Backups
We write more than 5,000 backups every day to encrypted long-term storage — about 150 terabytes of backup volume per month.
270 million user sessions
More than 9 million user sessions run through software we operate every day.
99,99% Uptime
Our managed services are unavailable for less than one hour per year on average.
MTTD < 5 minutes
Our alerting typically detects faults and outages within a few minutes.