Skip to main content
Cloud / STACKIT / Products / STACKIT Secrets Manager - Secure Credential Management

STACKIT Secrets Manager - Secure Credential Management

STACKIT Secrets Manager: Secure management of API keys, passwords, certificates. Versioning, audit logs, GDPR compliant.

Security
Pricing Model Hourly billing based on capacity tier (e.g. 100, 1k, 10k, 100k, 1M secrets)
Availability Germany (STACKIT regions)
Data Sovereignty 100% German data centers
Reliability SLA as published by the provider SLA

What is STACKIT Secrets Manager?

STACKIT Secrets Manager is a fully managed service that provides a secure key-value store for sensitive data such as passwords, API keys, certificates, and configuration parameters. The service enables separation of secrets from source code in line with common security requirements. STACKIT operates the service exclusively in German data centers for complete GDPR compliance.

Core Features

  • Centralized, encrypted key-value store for secrets, separate from source code
  • Versioning of secrets for traceability and rollback
  • API modeled on the HashiCorp Vault KV2 interface
  • Integration with tools such as Terraform
  • KMS integration for encrypting stored secrets
  • Managed high-availability infrastructure with automatic updates

Typical Use Cases

Database Credentials for Microservices: Instead of storing passwords in environment variables, credentials are retrieved from Secrets Manager at runtime.

API Keys for External Services: Payment providers, email services, and cloud APIs require API keys. Secrets Manager stores these encrypted and versioned for quick rollback.

Centralized Configuration Management: Application configurations and credentials are managed centrally and distributed across environments (dev, staging, production) via the API.

Benefits

  • Complete data sovereignty in German data centers
  • Versioning for quick rollback in case of faulty changes
  • Compatibility with existing Vault-based workflows through a KV2-compatible API
  • GDPR compliant with an audit trail

Integration with innFactory

As an official STACKIT partner, innFactory supports you with STACKIT Secrets Manager: architecture, migration, operations, and cost optimization.

Available Tiers & Options

Typical Use Cases

API key management
Database credential storage
Certificate management
Application configuration
Service account credentials
Multi-environment secrets

Frequently Asked Questions

What is STACKIT Secrets Manager?

STACKIT Secrets Manager is a managed key-value store for protecting and managing sensitive data such as passwords, API keys, and configuration files, kept separate from source code.

How are secrets encrypted?

Secrets are stored encrypted server-side, with encryption configurable via a KMS integration. Configuration details are documented in the current STACKIT documentation.

Is the API compatible with HashiCorp Vault?

The Secrets Manager API is modeled on the HashiCorp Vault KV2 API, allowing existing Vault CLI workflows and tools to be reused with adjustments.

How do applications access secrets?

Access happens via an API as well as integrations with common tools such as Terraform. For production use, check the current integration documentation for your target system.

Is STACKIT Secrets Manager GDPR compliant?

Yes, the service operates exclusively in German data centers. STACKIT provides data processing agreements and is ISO 27001 certified.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of STACKIT (official documentation). This page does not represent an offer by STACKIT.

STACKIT Partner

innFactory is an official STACKIT Partner. We provide consulting, implementation, and managed services for the sovereign cloud.

STACKIT Official Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

Google Cloud

Access Approval - Google Cloud Access Control

Access Approval for Google Cloud: manual approval before support accesses your data. Transparency and control for GDPR …

Pricing No extra cost, requires at least …
SLA SLA as published by the provider
Compare →
Google Cloud

Access Transparency - Access Logging

Access Transparency logs Google personnel access to your cloud data. Transparency and compliance for regulated …

Pricing No extra cost, requires at least …
SLA SLA as published by the provider
Compare →
Google Cloud

AI Protection - AI Security

AI Protection in Security Command Center inventories AI assets, scores AI risks via attack-path simulation, and detects …

Pricing Included in SCC Premium/Enterprise, no …
SLA N/A (part of Security Command Center)
Compare →
AWS

Amazon Cognito: User Authentication

Amazon Cognito provides user authentication and identity management for web and mobile apps.

Pricing Pay-per-use based on monthly active …
SLA SLA as published by the provider
Compare →
AWS

Amazon Detective - Security Analysis

Amazon Detective analyzes security data and assists with investigating security incidents in AWS environments.

Pricing Tiered pricing per GB of ingested data, …
SLA SLA as published by the provider
Compare →
AWS

Amazon GuardDuty - Threat Detection

Amazon GuardDuty detects threats in AWS accounts via ML-based analysis of logs, runtime activity, and data access.

Pricing Pay-per-use: foundational protection …
SLA SLA as published by the provider
Compare →

61 comparable products found across other clouds.

Ready to start with STACKIT Secrets Manager - Secure Credential Management?

Our certified STACKIT experts help you with architecture, integration, and optimization.

Schedule Consultation