ayedo Secrets Management – OpenBao

Secrets Management
Made in Germany

ayedo operates OpenBao for your secrets, certificates, and dynamic credentials – central, auditable, and part of your Software Delivery Platform. You use the APIs; operations and availability stay with us.

Leading companies trust our technology ↘

Manage secrets securely

Our secrets management is based on OpenBao in the platform cluster – central secrets without in-house build-out, predictable instance costs, and developers without vault ops. ayedo handles day-2 including auto-unseal and Kubernetes integration.

Static Secrets

API keys & passwords

OpenBao provides a central store for your credentials – with versioning, lease management, and a full audit log. Secrets no longer need to live in Git repositories or ConfigMaps.
KV Credentials Audit

Dynamic Secrets

Short-lived access

Database credentials, cloud IAM roles, and service accounts are created on demand, rotated automatically, and can be revoked at any time.
Dynamic Rotation IAM

PKI & Certificates

TLS as a service

An internal certificate authority issues certificates for mTLS, service mesh, and ingress – issuance and renewal are fully automated.
PKI TLS mTLS

Encryption as a Service

Transit engine

The transit engine encrypts sensitive data at rest and in transit – without requiring you to build your own key management infrastructure.
Transit Encryption KMS

Kubernetes Integration

Native for Kubernetes

The External Secrets Operator syncs your secrets into workload clusters – either as Kubernetes secrets or as mounted files.
K8s ESO Operator

EU Infrastructure

Sovereign hosting

Your key material and secrets remain on European infrastructure – GDPR-compliant and independent of US cloud providers.
EU GDPR Sovereignty

Pricing

Managed OpenBao is available as part of the ayedo platform – in the ayedo Cloud, on a dedicated cluster, or on your own infrastructure (BYOC/on-premises).

ayedo Cloud

Shared platform · Multi-tenant

€199.95 /month

  • €199.95/month per OpenBao instance
  • HA setup with auto-unseal
  • Kubernetes secrets sync (ESO)
  • Audit logging included
  • OIDC via ayedo ID
  • Operated in the central Platform Cluster

Dedicated

Dedicated cluster · Single-tenant

from €199.95 /month

  • from €199.95/month per cluster
  • OpenBao in a dedicated Platform Cluster
  • Your own, fully isolated instance
  • Custom namespaces & policies
  • Disaster recovery between regions
  • Custom SLAs

BYOC / On-Premises

On your infrastructure

Custom

  • OpenBao in your cloud or on-premises
  • Optional HSM integration
  • Support for air-gapped environments
  • Enterprise support
  • Prepared for your compliance requirements
  • Custom SLAs

Compare with alternatives

Managed OpenBao on the ayedo platform provides sovereign secrets management on European infrastructure – cloud-agnostic and independent of any single cloud provider.

vs. AWS Secrets Manager

Kriterium ayedo AWS Secrets Manager
Jurisdiction
EU / GDPR-compliant
US / Cloud Act
Multi-cloud
Cloud-agnostic
AWS-only
Dynamic secrets
OpenBao engines
Limited
PKI
Built-in
ACM separate

vs. Azure Key Vault

Kriterium ayedo Azure Key Vault
Vendor lock-in
Open ecosystem
Azure-focused
Kubernetes
Native operator / ESO
Azure-specific
On-premises / BYOC
Available
Cloud-first
Support
Personal, in German/English
Ticket system

vs. GCP Secret Manager

Kriterium ayedo GCP Secret Manager
Jurisdiction
EU hosting
US company
Encryption
Transit + KMS
Cloud KMS
Audit
Full audit log
Cloud Logging
Pricing transparency
Fixed per instance
Per secret/op

Compliance & Regulatory Requirements

The ayedo Software Delivery Platform meets the requirements of current EU regulations. From GDPR to NIS-2 to DORA – our platform is designed for regulated industries and critical infrastructures.

GDPR-Compliant Data Processing

Privacy by Design & Default.

EU data residency (Germany), Customer-Managed Keys (BYOK/BYOHSM), encryption at rest/in transit. ISO 27001-certified data protection management. Support for data subject rights, DPA, incident response. More about GDPR .

NIS-2-Compliant Operations

Resilience for critical infrastructures.

24/7 monitoring, incident response, BCP/DR processes, supply chain transparency (SBOM). EU-based operations, MFA/PAM, vulnerability management, patch processes. Ideal for essential/important entities. More about NIS-2 .

DORA-Ready for Financial Institutions

ICT resilience tailored.

ICT risk management framework, documented exit strategies, third-party risk management, TLPT readiness. Structured incident reporting chains, continuous resilience testing, ISO 27001-certified. More about DORA .

CRA-Compliant Software Supply Chain

Security by Design across the entire lifecycle.

SBOM generation, CVE scanning, vulnerability disclosure processes, update management. Signed container images, GitOps-based audit trails, transparent supply chain. More about CRA .

Cloud Sovereignty Framework

Digital sovereignty made measurable.

EU-based operations, open standards, exit capability without lock-in. Designed for SEAL-4 (Full Digital Sovereignty) across all eight sovereignty objectives. No dependencies on non-EU control. More about the Framework .

Data Act-Compliant Portability

Switching without barriers.

Open APIs (OpenAPI), standardized formats (YAML/JSON/OCI), complete exit runbooks, Infrastructure-as-Code portability. Multi-cloud capable, no egress fees, functional equivalence. More about Data Act .

Integrated Compliance Roadmap

Holistic approach.

How ayedo systematically addresses GDPR, NIS-2, DORA, CRA, Data Act, Cloud Sovereignty Framework, ISO 27001/9001. Certifications, processes, technical measures, audit readiness. To overview .

Part of the Software Delivery Platform

OpenBao is a core pillar for Identity , Code Repository , Delivery , and all Managed Apps – because secrets do not belong in Git repositories.

Identity

OIDC access

Access to OpenBao is provided via ayedo ID or your dedicated Keycloak – without additional local user accounts.
OIDC Keycloak SSO

Managed Kubernetes

Secrets for workloads

Your secrets are synced automatically into your workload clusters – no manual copying required.
Kubernetes ESO Sync

Delivery

GitOps-safe deployments

Argo CD pulls secrets directly from OpenBao – so no credentials end up in your Git repositories.
ArgoCD GitOps Security
https://icons.ayedo.de/svg/openbao.svg

OpenBao App

Managed app details

You can find the technical specification and block reference on the OpenBao managed app page.
OpenBao Managed App

You build it. We run it.

Excellent performance and maximum uptime - that’s what we wake up for. And sometimes even in the middle of the night.

100+ Clusters

under management

We operate more than 100 Kubernetes clusters in production for our customers.

300+ Databases

under management

We operate, monitor, and back up more than 300 databases in production.

1 Petabyte Object Storage

under management

We operate one petabyte of object storage for backups, artifacts, and application data.

100 Million Timeseries

on average

4 million datapoints per second are ingested by our monitoring systems.

38,000+ Logs

per second

Our collectors continuously ingest logs and store them in a GDPR-compliant way – more than 100 billion entries per month.

5,000+ Backups

per day

We secure more than 5,000 backups every day on encrypted long-term storage – around 150 terabytes of backup volume per month.

270 Million End Users

per month

More than 9 million end users use software we deploy every day, on the internet or on-premise.

99.99% Uptime

annual average

Our managed services are unavailable for less than 1 hour per year on average.

MTTD < 5 Minutes

on average

Our alerting typically detects errors and outages within a few minutes.
Kontakt aufnehmen