Best Encryption Key Management Software

How Many Encryption Key Management Software Products Does G2 Track?

Total Products under this Category: 70

Category Stats (Sep 2026)

  • Average Rating: 4.46/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Thales CipherTrust Data Security Platform (+0.74%) - Among all products in this category, Thales CipherTrust Data Security Platform recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Encryption Key Management Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 2,400+ Authentic Reviews
  • 70+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Encryption Key Management Software

G2 Grid® for Encryption Key Management Software plotting products by satisfaction and market presence

Highlighted products: Egnyte, Doppler secrets management platform, AWS Key Management Service (KMS), Google Cloud Key Management Service, Thales CipherTrust Data Security Platform, Azure Key Vault, DigiCert ONE, and Akeyless Identity Security Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/encryption-key-management/grids.json?focus%5B%5D=egnyte&focus%5B%5D=doppler-secrets-management-platform&focus%5B%5D=aws-key-management-service-kms&focus%5B%5D=google-cloud-key-management-service&focus%5B%5D=thales-ciphertrust-data-security-platform&focus%5B%5D=azure-key-vault&focus%5B%5D=digicert-one&focus%5B%5D=akeyless-identity-security-platform)

Egnyte

Egnyte combines the power of cloud content management, data security, and AI into one intelligent content platform. More than 22,000 customers trust Egnyte to improve employee productivity, automate business processes, and safeguard critical data, in addition to offering specialized content intelligence and automation solutions across industries, including architecture, engineering, and construction (AEC), life sciences, and financial services.

Average Rating: 4.4/5.0

Total Reviews: 1,140

How Do G2 Users Rate Egnyte?

  • Regional Support: 9.0/10 (Category avg: 8.6/10)
  • Scalability: 9.0/10 (Category avg: 8.7/10)
  • API/Integrations: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 9.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Egnyte?

  • Seller: Egnyte
  • Company Website:
  • Year Founded: 2008
  • HQ Location: Mountain View, CA
  • Twitter: @Egnyte
    16,127 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,309 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Project Manager, Owner
  • Top Industries: Construction, Marketing and Advertising
  • Company Size: 44% Small, 38% Medium

What Do G2 Reviewers Say About Egnyte?

AI-generated summary from verified user reviews

Pros
  • Users find Egnyte to be user-friendly and easy to navigate, enhancing their overall experience and efficiency.
  • Users love the easy file sharing capabilities of Egnyte, enhancing collaboration and workflow efficiency from anywhere.
  • Users appreciate the easy sharing capabilities of Egnyte, enhancing collaboration across departments with secure file access.
  • Users enjoy the easy access to files anywhere, ensuring productivity with a secure and reliable platform.
  • Users commend Egnyte for its high security, ensuring data safety while navigating and finding files easily.
Cons
  • Users find Egnyte expensive, especially when storage needs exceed small business plan limits without clear ROI.
  • Users experience file saving failures, timeouts, and duplication issues, which detracts from their overall experience with Egnyte.
  • Users find user difficulty with Egnyte, especially on mobile, complicating the overall experience and feature accessibility.
  • Users find Egnyte lacking features like clear visibility on team documents and effective handling of file sharing tasks.
  • Users are disappointed by the missing features in Egnyte, especially for 3D file support and collaboration.

What Are Recent G2 Reviews of Egnyte?

What Are G2 Users Discussing About Egnyte?

Doppler secrets management platform

Doppler is a centralized, secure secrets management platform tailored for DevOps engineers and CTOs at mid-market and enterprise companies. Secrets sprawl and fragmented processes can create significant risks, inefficiencies, and operational headaches. Doppler tackles these issues by consolidating secret management into a single, secure platform, ensuring reliability and consistency across teams and environments. Doppler’s mission reflects its core value: replacing disorganized, high-risk workflows with a unified, reliable system. With Doppler, teams can better manage their secrets while fostering security and operational stability. Managing secrets across diverse systems can often feel overwhelming. Doppler eliminates this complexity by organizing and securing sensitive data in one place. Its unified interface allows teams to maintain control over their secrets, enforce security best practices, and reduce the likelihood of misconfigurations or breaches. Doppler provides a structured and dependable solution to secrets management by addressing key challenges like: - Manual secret rotations - Synchronization issues - Compliance tracking Integration with popular tools and workflows is central to Doppler’s design. This ensures compatibility without disrupting established processes. This reduces operational bottlenecks, helping teams maintain productivity and focus on deploying critical applications. Connect with tools like: - Kubernetes - Terraform - CI/CD pipelines Its built-in logging and audit trails reduce the burden of manual compliance tasks, allowing teams to focus on strategic initiatives rather than administrative overhead. The platform also enhances visibility by providing insights into secret usage and access, ensuring that no detail is overlooked. For organizations concerned with compliance, Doppler simplifies the process of meeting industry standards such as: - SOC 2 - HIPAA - GDPR - ISO Doppler delivers a dependable way to centralize and safeguard secrets, reducing the risk of operational disruptions while maintaining compliance. Whether managing daily operations or scaling infrastructure, Doppler ensures your organization is prepared to handle the challenges of modern development environments. By bringing security, organization, and clarity to secret management, Doppler empowers teams to focus on what truly matters—driving innovation and delivering impactful results.

Average Rating: 4.8/5.0

Total Reviews: 96

How Do G2 Users Rate Doppler secrets management platform?

  • Regional Support: 7.8/10 (Category avg: 8.6/10)
  • Scalability: 9.7/10 (Category avg: 8.7/10)
  • API/Integrations: 9.6/10 (Category avg: 8.5/10)
  • Ease of Use: 9.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Doppler secrets management platform?

  • Seller: Doppler
  • Company Website:
  • Year Founded: 2018
  • HQ Location: San Francisco, California
  • Twitter: @doppler
    1,586 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    49 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CTO
  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 74% Small, 24% Medium

What Do G2 Reviewers Say About Doppler secrets management platform?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Doppler, appreciating its straightforward integration and smooth setup across environments.
  • Users love the easy integrations of Doppler, streamlining workflow and enhancing efficiency across tools and environments.
  • Users value the seamless integrations of Doppler, enhancing efficiency and workflow management across platforms.
  • Users value the seamless synchronization capabilities of Doppler, making secret management effortless across environments.
  • Users value the easy access management while ensuring secure protection for sensitive data against threats.
Cons
  • Users find the complex setup requires technical expertise, making it challenging and costly for medium businesses.
  • Users find the platform expensive for medium businesses, requiring technical expertise for setup and maintenance.
  • Users find limited OS compatibility challenging, especially with complex setup processes on Windows compared to Linux.
  • Users find the setup process challenging in Windows, noting easier implementation on Linux environments instead.

What Are Recent G2 Reviews of Doppler secrets management platform?

What Are G2 Users Discussing About Doppler secrets management platform?

AWS Key Management Service (KMS)

AWS Key Management Service (KMS) is a service that help to create and control the encryption keys used to encrypt data, and uses Hardware Security Modules (HSMs) to protect the security of keys.

Average Rating: 4.4/5.0

Total Reviews: 31

How Do G2 Users Rate AWS Key Management Service (KMS)?

  • Regional Support: 10.0/10 (Category avg: 8.6/10)
  • Scalability: 9.4/10 (Category avg: 8.7/10)
  • API/Integrations: 9.2/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind AWS Key Management Service (KMS)?

  • Seller: Amazon Web Services (AWS)
  • Year Founded: 2006
  • HQ Location: Seattle, WA
  • Twitter: @awscloud
    2,232,483 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    147,094 employees on LinkedIn®
  • Ownership: NASDAQ: AMZN

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 59% Large, 21% Medium

What Do G2 Reviewers Say About AWS Key Management Service (KMS)?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the abundance of services offered by AWS, enhancing their cloud capabilities significantly.
  • Users appreciate the extensive range of services offered by AWS KMS, enhancing security and architecture capabilities.
  • Users appreciate the robust security features of AWS KMS, enhancing their protection against various cyber threats.
Cons
  • Users report access issues with AWS KMS, experiencing failures in protection during DDoS attack simulations.
  • Users report connectivity issues with AWS KMS, particularly during DDoS attack simulations, impacting resource accessibility.

What Are Recent G2 Reviews of AWS Key Management Service (KMS)?

What Are G2 Users Discussing About AWS Key Management Service (KMS)?

Google Cloud Key Management Service

Manage encryption keys on Google Cloud Platform

Average Rating: 4.6/5.0

Total Reviews: 16

How Do G2 Users Rate Google Cloud Key Management Service?

  • Regional Support: 7.7/10 (Category avg: 8.6/10)
  • Scalability: 8.6/10 (Category avg: 8.7/10)
  • API/Integrations: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Google Cloud Key Management Service?

  • Seller: Google
  • Year Founded: 1998
  • HQ Location: Mountain View, CA
  • Twitter: @google
    31,899,995 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    301,144 employees on LinkedIn®
  • Ownership: NASDAQ:GOOG

Who Uses This Product?

  • Company Size: 53% Large, 29% Small

What Do G2 Reviewers Say About Google Cloud Key Management Service?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the easy file storage and sharing with Google Cloud Key Management Service, enhancing efficiency with one-click functionality.
  • Users value the easy access for storing and sharing heavy files effortlessly with Google Cloud Key Management Service.
Cons
  • Users experience slow performance when uploading heavy files, with occasional failures that hinder productivity.

What Are Recent G2 Reviews of Google Cloud Key Management Service?

What Are G2 Users Discussing About Google Cloud Key Management Service?

Thales CipherTrust Data Security Platform

Thales CipherTrust Data Security Platform (CDSP) removes the complexity from enterprise data security by unifying discovery, analysis, protection, and control in a single, modern platform. Built on a cloud-native, microservices architecture, CipherTrust Data Security Platform is designed to secure sensitive data across on-premises, hybrid, cloud, and multi-cloud environments while accelerating time to compliance and enabling secure cloud migrations. It brings together data discovery and classification, encryption, tokenization, granular access controls, and centralized key management - reducing operational overhead and consolidating previously siloed tools. Discover: Scans structured and unstructured data across on-prem, cloud, and hybrid environments to locate sensitive data (PII, financial records, etc.), giving you visibility into where critical data actually lives. Analyze: Assesses risk by attaching context to discovered data, helping prioritize what needs protection based on sensitivity, regulatory exposure, and access patterns. Protect: Applies encryption, tokenization, and key management to secure data at rest, in transit, and in use with minimal disruption. Control: Enforces granular access policies and provides detailed audit logs, enabling strict governance, separation of duties, and compliance reporting across the entire data lifecycle. CipherTrust Data Security Platform supports flexible deployment models - on-premises, hybrid, or as-a-service - so organizations can align security with operational requirements. By consolidating data-centric security capabilities into a single platform, CDSP reduces risk and provides a clear, scalable path to comprehensive data security.

Average Rating: 4.4/5.0

Total Reviews: 22

How Do G2 Users Rate Thales CipherTrust Data Security Platform?

  • Regional Support: 8.8/10 (Category avg: 8.6/10)
  • Scalability: 9.3/10 (Category avg: 8.7/10)
  • API/Integrations: 9.7/10 (Category avg: 8.5/10)
  • Ease of Use: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Thales CipherTrust Data Security Platform?

  • Seller: Thales Group
  • Company Website:
  • HQ Location: Austin, Texas
  • Twitter: @ThalesCloudSec
    6,935 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    46 employees on LinkedIn®
  • Ownership: EPA:HO

Who Uses This Product?

  • Top Industries: Information Technology and Services, Financial Services
  • Company Size: 64% Large, 24% Small

What Are Recent G2 Reviews of Thales CipherTrust Data Security Platform?

What Are G2 Users Discussing About Thales CipherTrust Data Security Platform?

Azure Key Vault

Azure Key Vault is a cloud service designed to securely store and manage cryptographic keys, secrets, and certificates used by applications and services. It enables organizations to safeguard sensitive information such as API keys, passwords, and connection strings, ensuring that these secrets are protected and accessible only to authorized users and applications. By centralizing the management of keys and secrets, Azure Key Vault helps maintain compliance with security standards and simplifies the administration of cryptographic materials. Key Features and Functionality: - Secrets Management: Securely store and tightly control access to tokens, passwords, certificates, API keys, and other secrets. - Key Management: Easily create and control the encryption keys used to encrypt your data. - Certificate Management: Provision, manage, and deploy public and private Transport Layer Security/Secure Sockets Layer (TLS/SSL) certificates for use with Azure and your internal connected resources. - Access Control: Integrates with Azure Active Directory (Azure AD) to provide fine-grained access control through role-based access control (RBAC) and access policies. - Monitoring and Logging: Monitor and audit key usage with Azure logging—pipe logs into Azure HDInsight or your security information and event management (SIEM) solution for more analysis and threat detection. - Integration with Azure Services: Seamlessly integrates with other Azure services, such as Azure Storage, Azure SQL Database, and Azure App Service, allowing applications to retrieve and use secrets, certificates, and keys securely without needing to store sensitive information in application code or configuration files. Primary Value and Problem Solved: Azure Key Vault addresses the critical need for secure and efficient management of cryptographic keys and secrets in cloud environments. By centralizing the storage and access control of sensitive information, it reduces the risk of accidental leaks and unauthorized access. The service simplifies the process of key and secret management, allowing developers to focus on application development without the burden of implementing custom security solutions. Additionally, Azure Key Vault enhances compliance with security standards and regulations by providing robust access controls, monitoring capabilities, and integration with Azure's security ecosystem.

Average Rating: 4.5/5.0

Total Reviews: 47

How Do G2 Users Rate Azure Key Vault?

  • Regional Support: 8.9/10 (Category avg: 8.6/10)
  • Scalability: 8.9/10 (Category avg: 8.7/10)
  • API/Integrations: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Azure Key Vault?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Who Uses This: Software Engineer
  • Top Industries: Information Technology and Services, Accounting
  • Company Size: 50% Large, 25% Medium

What Are Recent G2 Reviews of Azure Key Vault?

What Are G2 Users Discussing About Azure Key Vault?

DigiCert ONE

DigiCert ONE is a cloud-native digital trust platform that helps organizations automate, manage, and secure certificates, identities, software, devices, DNS infrastructure, documents, and email communications from a single platform. Designed to simplify complex trust environments, DigiCert ONE provides centralized visibility, policy-based governance, and automation to reduce operational risk, improve compliance, and accelerate digital transformation initiatives. The platform includes: - Trust Lifecycle Manager for CA-agnostic certificate lifecycle management, certificate discovery, automation, and public and private PKI. - Software Trust Manager for secure code signing, software supply chain protection, and automated signing workflows. - Device Trust Manager for establishing and managing trusted device identities throughout the IoT and device lifecycle. - Content Trust Manager for digital signatures, electronic seals, timestamping, and document trust services. - UltraDNS for highly available, secure DNS infrastructure, intelligent traffic management, and application resiliency. - Messaging Trust for email authentication, domain protection, phishing prevention, and improved email deliverability. DigiCert ONE also integrates with CertCentral®, enabling organizations to streamline the issuance, management, and automation of publicly trusted TLS/SSL certificates alongside their broader digital trust operations. Built on a scalable, container-based architecture, DigiCert ONE supports cloud, on-premises, hybrid, and air-gapped deployments, enabling organizations to meet security, operational, and regulatory requirements while maintaining agility. Organizations use DigiCert ONE to eliminate manual trust management processes, prevent certificate-related outages, secure software and connected devices, protect critical infrastructure, and build trusted digital experiences at scale.

Average Rating: 4.3/5.0

Total Reviews: 72

How Do G2 Users Rate DigiCert ONE?

  • Ease of Use: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind DigiCert ONE?

  • Seller: DigiCert
  • Company Website:
  • Year Founded: 2003
  • HQ Location: Lehi, UT
  • Twitter: @digicert
    6,675 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,957 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 39% Small, 37% Medium

What Are Recent G2 Reviews of DigiCert ONE?

What Are G2 Users Discussing About DigiCert ONE?

Akeyless Identity Security Platform

Akeyless delivers identity security for an era shaped by automation and AI. The cloud-native platform secures machines, AI agents, and human access across hybrid, multi-cloud, and on-prem environments. It provides a practical path to secretless, identity-based access through secrets management, certificate lifecycle management and PKI, PAM, and unified governance. Akeyless is built on a cryptography foundation that combines encryption, key management, and Distributed Fragments Cryptography to keep sensitive material under customer control and protected from post-quantum threats. With integrations for cloud IAM, Kubernetes, CI/CD, and MCP-based AI agent workflows, teams can adopt and scale AI agents securely without expanding risk. Akeyless Jarvis™ delivers AI-powered identity intelligence to surface risky access and strengthen oversight.

Average Rating: 4.6/5.0

Total Reviews: 90

How Do G2 Users Rate Akeyless Identity Security Platform?

  • Regional Support: 9.4/10 (Category avg: 8.6/10)
  • Scalability: 9.4/10 (Category avg: 8.7/10)
  • API/Integrations: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Akeyless Identity Security Platform?

  • Seller: Akeyless
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Ramat Gan, Israel
  • Twitter: @akeylessio
    293 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    107 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 50% Large, 27% Medium

What Do G2 Reviewers Say About Akeyless Identity Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Akeyless Identity Security Platform enhances seamless integration with their existing systems.
  • Users value the robust security features of Akeyless, enhancing their infrastructure and ensuring efficient management.
  • Users praise the great customer support of Akeyless Identity Security Platform, enhancing their overall experience and satisfaction.
  • Users love the easy integrations with tools like Ansible and GCP, enhancing their DevOps efficiency and automation.
  • Users appreciate the ease of implementation of Akeyless Identity Security Platform, simplifying integration with existing systems.
Cons
  • Users find the poor documentation limits their ability to fully leverage the Akeyless Identity Security Platform.
  • Users find the poor UI of Akeyless Identity Security Platform hinders intuitive navigation and requires extra effort to use.
  • Users find the complex setup challenging, often requiring support to interpret issues from logs.
  • Users find the complex usage of Akeyless requires significant time and effort for effective integration into workflows.

What Are Recent G2 Reviews of Akeyless Identity Security Platform?

What Are G2 Users Discussing About Akeyless Identity Security Platform?

Virtru Email Encryption

Secure data directly from your inbox with Virtru. Users can easily encrypt emails and attachments with just one click, protecting sensitive data such as personally identifiable information (PII), intellectual property, and other regulated information. Seamlessly integrating with platforms like Gmail and Microsoft Outlook, Virtru empowers organizations to meet compliance requirements for HIPAA, GDPR, CJIS, CMMC 2.0, ITAR and other data privacy regulations, without disrupting existing workflows. Virtru provides full control over email content even after it’s been sent. Users can set expiration dates, revoke access, and track where emails are shared, ensuring total visibility and control over sensitive information. With granular access control and audit trails, Virtru simplifies data protection for enterprises and small businesses alike. Ideal for industries such as healthcare, financial services, government, and education, Virtru empowers your teams to confidently share sensitive information without sacrificing security.

Average Rating: 4.4/5.0

Total Reviews: 430

How Do G2 Users Rate Virtru Email Encryption?

  • Regional Support: 8.3/10 (Category avg: 8.6/10)
  • Scalability: 8.3/10 (Category avg: 8.7/10)
  • API/Integrations: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Virtru Email Encryption?

  • Seller: Virtru
  • Company Website:
  • Year Founded: 2012
  • HQ Location: Washington, DC
  • Twitter: @virtruprivacy
    1,790 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    266 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Office Manager, Administrative Assistant
  • Top Industries: Hospital & Health Care, Health, Wellness and Fitness
  • Company Size: 45% Medium, 38% Small

What Do G2 Reviewers Say About Virtru Email Encryption?

AI-generated summary from verified user reviews

Pros
  • Users enjoy the ease of use of Virtru Email Encryption, benefiting from simple setup and minimal effort required.
  • Users value the security features of Virtru Email Encryption, ensuring only intended recipients can access encrypted emails.
  • Users value the ease of use and reliability of Virtru Email Encryption for secure email communication.
  • Users value the easy-to-use and reliable functionality of Virtru Email Encryption for securing confidential communications.
  • Users value the secure communication provided by Virtru Email Encryption, ensuring confidentiality and peace of mind for sensitive information.
Cons
  • Users face email issues with Virtru, including unreliable sending and disruptive disconnections that hinder professional use.
  • Users find it challenging to open encrypted emails, encountering encryption issues that hinder communication with others.
  • Users face access issues with Virtru Email Encryption, finding the process cumbersome and clients often struggling to use it.
  • Users find encryption issues frustrating, especially for older individuals and when recipients do not use Virtru.
  • Users face access limitations with Virtru Email Encryption, finding it cumbersome to open emails and requiring client sign-ins.

What Are Recent G2 Reviews of Virtru Email Encryption?

What Are G2 Users Discussing About Virtru Email Encryption?

IBM Vault (formerly HashiCorp Vault)

IBM Vault (formerly HashiCorp Vault) tightly controls access to secrets and encryption keys by authenticating against trusted sources of identity such as Active Directory, LDAP, Kubernetes, CloudFoundry, and cloud platforms. Vault enables fine grained authorization of which users and applications are permitted access to secrets and keys. Some of Vault's main use cases include: - Secrets Management - Identity Brokering - Data Encryption

Average Rating: 4.3/5.0

Total Reviews: 53

How Do G2 Users Rate IBM Vault (formerly HashiCorp Vault)?

  • Regional Support: 8.8/10 (Category avg: 8.6/10)
  • Scalability: 8.7/10 (Category avg: 8.7/10)
  • API/Integrations: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 7.7/10 (Category avg: 8.8/10)

Who Is the Company Behind IBM Vault (formerly HashiCorp Vault)?

  • Seller: HashiCorp
  • Company Website:
  • Year Founded: 2012
  • HQ Location: San Francisco, CA
  • Twitter: @hashicorp
    103,221 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    9,110 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 39% Large, 35% Medium

What Do G2 Reviewers Say About IBM Vault (formerly HashiCorp Vault)?

AI-generated summary from verified user reviews

Pros
  • Users value the superior security features of IBM Vault, enhancing integration and management capabilities effortlessly.
  • Users appreciate the ease of use of IBM Vault, praising its simplicity and effective management features.
  • Users appreciate the easy integrations and native capabilities of IBM Vault, enhancing their security and usability.
  • Users appreciate the native integrations and capabilities of IBM Vault, enhancing security and ease of use.
  • Users find IBM Vault's easy setup and robust security features invaluable for managing sensitive credentials effectively.
Cons
  • Users find the complexity of IBM Vault challenging, particularly for those who are new to the system.
  • Users find the complex usage of IBM Vault challenging, especially those who are new to the platform.
  • Users find IBM Vault to be expensive when seeking full enterprise capabilities, which can hinder accessibility.
  • Users find the learning curve steep, making it challenging for beginners to understand Vault effectively.
  • Users find that the learning difficulty of IBM Vault can be challenging for beginners to grasp effectively.

What Are Recent G2 Reviews of IBM Vault (formerly HashiCorp Vault)?

What Are G2 Users Discussing About IBM Vault (formerly HashiCorp Vault)?

Oracle Cloud Infrastructure Vault

Oracle Cloud Infrastructure Key Management is a managed service that enables you to encrypt your data using keys that you control.

Average Rating: 4.3/5.0

Total Reviews: 35

How Do G2 Users Rate Oracle Cloud Infrastructure Vault?

  • Regional Support: 8.2/10 (Category avg: 8.6/10)
  • Scalability: 8.3/10 (Category avg: 8.7/10)
  • API/Integrations: 9.3/10 (Category avg: 8.5/10)
  • Ease of Use: 8.4/10 (Category avg: 8.8/10)

Who Is the Company Behind Oracle Cloud Infrastructure Vault?

  • Seller: Oracle
  • Year Founded: 1977
  • HQ Location: Austin, TX
  • Twitter: @Oracle
    827,997 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    207,576 employees on LinkedIn®
  • Ownership: NYSE:ORCL

Who Uses This Product?

  • Top Industries: Computer Software, Information Technology and Services
  • Company Size: 44% Small, 31% Large

What Are Recent G2 Reviews of Oracle Cloud Infrastructure Vault?

AWS CloudHSM

AWS CloudHSM is a cloud-based hardware security module (HSM) that enables you to easily generate and use your own encryption keys on the AWS Cloud.

Average Rating: 4.3/5.0

Total Reviews: 13

How Do G2 Users Rate AWS CloudHSM?

  • Regional Support: 6.7/10 (Category avg: 8.6/10)
  • Scalability: 8.3/10 (Category avg: 8.7/10)
  • API/Integrations: 9.2/10 (Category avg: 8.5/10)
  • Ease of Use: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind AWS CloudHSM?

  • Seller: Amazon Web Services (AWS)
  • Year Founded: 2006
  • HQ Location: Seattle, WA
  • Twitter: @awscloud
    2,232,483 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    147,094 employees on LinkedIn®
  • Ownership: NASDAQ: AMZN

Who Uses This Product?

  • Company Size: 36% Large, 36% Small

What Are Recent G2 Reviews of AWS CloudHSM?

What Are G2 Users Discussing About AWS CloudHSM?

Azure Confidential Computing

Azure confidential computing offers solutions to enable the isolation your sensitive data while it's being processed in the cloud. Learn how to create and deploy applications based on confidential computing infrastructure by reading concepts, completing tutorials, and working with code samples. Use Microsoft products built on confidential computing to keep your workloads as secure as possible.

Average Rating: 4.3/5.0

Total Reviews: 15

How Do G2 Users Rate Azure Confidential Computing?

  • Ease of Use: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Azure Confidential Computing?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 40% Large, 33% Small

What Are Recent G2 Reviews of Azure Confidential Computing?

What Are G2 Users Discussing About Azure Confidential Computing?

Box KeySafe

With Box KeySafe, you have complete, independent control over your encryption keys, with no impact to the user experience.

Average Rating: 4.0/5.0

Total Reviews: 14

How Do G2 Users Rate Box KeySafe?

  • Regional Support: 8.3/10 (Category avg: 8.6/10)
  • Scalability: 8.3/10 (Category avg: 8.7/10)
  • API/Integrations: 8.3/10 (Category avg: 8.5/10)
  • Ease of Use: 9.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Box KeySafe?

  • Seller: Box
  • Year Founded: 1998
  • HQ Location: Redwood City, CA
  • Twitter: @Box
    78,537 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4,413 employees on LinkedIn®
  • Ownership: NYSE:BOX

Who Uses This Product?

  • Company Size: 57% Small, 29% Large

What Are Recent G2 Reviews of Box KeySafe?

What Are G2 Users Discussing About Box KeySafe?

Keyfactor Command

Keyfactor Command is a certificate lifecycle management solution that enables organizations to discover, control, and automate the lifecycle of keys and digital certificates across their IT landscape. It's the only solution that can be deployed on-premise, in the cloud, in a hybrid model, or in combination with a fully hosted PKI as a Service. The solution is also available in the Azure and AWS Marketplaces.

Average Rating: 4.5/5.0

Total Reviews: 82

How Do G2 Users Rate Keyfactor Command?

  • Regional Support: 8.1/10 (Category avg: 8.6/10)
  • Scalability: 8.6/10 (Category avg: 8.7/10)
  • API/Integrations: 8.8/10 (Category avg: 8.5/10)
  • Ease of Use: 8.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Keyfactor Command?

  • Seller: Keyfactor
  • Company Website:
  • Year Founded: 2001
  • HQ Location: Independence, Ohio
  • Twitter: @Keyfactor
    1,780 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    596 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 80% Large, 12% Medium

What Are Recent G2 Reviews of Keyfactor Command?

What Are G2 Users Discussing About Keyfactor Command?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024

Learn More About Encryption Key Management Software

What is Encryption Key Management Software?

Encryption key management software assists companies with protecting and managing their cryptographic keys used for encrypting data on devices and in applications. Encryption key management software manages encryption keys throughout a key pair’s lifecycle, which includes key generation, exchange, use, integrity, availability, storage, backup or archive, revocation, and deregistration or destruction. On the backend, these tools manage encryption key generation, distribution, and replacement, while on the client side, the tools inject encryption keys and store and manage them on devices. These software solutions protect the keys by ensuring that only authenticated and authorized users can access them, preventing them from being disclosed, lost, misused, or intercepted by unauthorized parties.

What Do KMS and HSM Stand For?

KMS stands for key management systems. Key management systems are centralized hubs that manage the key lifecycle, including generation, certification, storage, usage, expiration, revocation, and retirement. Centralized key management systems work in conjunction with hardware security modules (HSMs). KMS may also be known by the following acronyms: CKMS, which is cryptographic key management system, or EKMS, which stands for enterprise key management system.

HSM stands for hardware security modules. Hardware security modules are servers built to be tamper-resistant or tamper-proof. HSMs generate, retrieve, share, and protect keys. These are considered the most secure key storage as these are physically built to prevent tampering by using special tamper-resistant screws and sealants.

What Types of Encryption Key Management Software Exist?

On-premises encryption key management

Some companies opt to store their key manager on-premises using a hardware security module (HSM), which is a server built to be tamper-resistant or tamper-proof. 


Cloud-based encryption key management

Some companies have complex key management needs and need a solution that scales to meet the volume and complexity of their encryption key transaction needs. Centralized cloud-based encryption key management can assist with symmetric and asymmetric key management and work with various databases, applications, and standards. Bring your own encryption (BYOE) or bring your own key (BYOK) is akin to the bring your own device (BYOD) security models—companies bring their own encryption key management software to deploy on public cloud infrastructure. However, this security model has trade-offs as this may entail giving cloud providers access to keys, which may not meet a company’s security policies. 

Key management as a service

Some cloud providers offer their own key management as a service solution in their cloud environments.

What are the Common Features of Encryption Key Management Software?

The following are some core features within encryption key management software:

Interoperability: For companies that use multiple types of cryptographic keys and multiple software applications, interoperability is important. Many encryption key management solutions are based on standard protocols, including Key Management Interoperability Protocol (KMIP) standard or Public Key Crypto Standard (PKCS 11). Other solutions will rely on closed-source key management.

Policy management: Companies may have specific policies for their encryption keys, including when to expire or revoke them or methods to prevent sharing the keys. Encryption key management software will enforce these policies.

Access management: In addition to creating and managing the keys themselves, it is important to manage who has access permissions to those keys. Many companies employ a least-privilege policy where users and systems have the least access needed to achieve their role function. Encryption key management solutions can enforce those policies, ensuring that only authorized and authenticated users or systems have access to the keys can prevent misuse. These tools will also provide access and audit logs.

Backup: If the keys are lost, access to the encrypted data will be unrecoverable without backup. Many encryption key management solutions offer backup features.

What are the Benefits of Encryption Key Management Software?

If not properly managed, encryption keys can fall into the wrong hands and be used to decrypt sensitive data. This can risk sensitive encrypted data or disrupt critical business information access. Managing encryption keys manually can be challenging to meet today’s business needs as the scale and complexity of applications used and the encryption and keys needed to secure those have grown, which is why many companies have opted for automated management solutions. If data encryption key management is managed manually, this time-consuming task may come at the expense of speed, availability, interoperability, accuracy, and integrity. 

Security: The main purpose of encryption and, therefore, encryption key management is security. Encryption key management software assists in managing encryption keys at scale in a secure manner and remains available to meet business needs.

Meeting regulatory compliance: Some highly regulated industries are bound by various data protection regulations for storing and managing encryption keys. Using encryption key management software, companies can meet requirements of regulations such as PCI DSS 3.2.1, NIST 800-53, and NIST 800-57.

Scalability: Today’s businesses rely on multiple devices and applications needing encryption, meaning they need an encryption key management solution that scales at speed to generate, distribute, and manage the keys. This can mean the ability to generate hundreds of keys per minute. Many businesses require low latency and high availability for their keys.

Who Uses Encryption Key Management Software?

Information security professionals: Information security professionals use encryption key management solutions which may include on-premises solutions like HSMs, centralized cloud-based solutions, or cloud-infrastructure-specific software-as-a-service solutions.

IT professionals: If a company does not have a dedicated information security (infosec) team, the responsibility for managing encryption keys falls on information technology (IT) teams.

Software Related to Encryption Key Management Software

Related solutions that can be used together with or as an alternative encryption key management software include:

Encryption software: Companies use encryption software to protect the confidentiality and integrity of their data. Encryption software will turn plaintext into cipher text using encryption. Keys to unencrypt the data will be stored using encryption key management solutions.

Email encryption software: To protect the confidentiality of data in transit, companies use email encryption software. Companies can use encryption key management solutions to protect the encryption keys. 

Certificate lifecycle management (CLM) software: Public key infrastructure (PKI) is an asymmetric encryption key management system that utilizes digital certificates such as SSL or TLS certificates and public keys to secure assets like website traffic.

Secrets management tools: Developer and DevOps teams, in particular, may utilize secrets management tools to store sensitive digital assets, such as encryption keys.

Challenges with Encryption Key Management Software

BYOE or BYOK: Companies must carefully understand who has access to their encryption keys. When utilizing a BYOE or BYOK security model, it is important to know who has access to the keys, including providers.

Scalability and availability: It is important to ensure that generating, managing, utilizing, and retiring encryption keys meets your company’s scale and availability requirements.

Backup: If encryption keys are lost, companies must have a backup plan. Ensure the software solution you are evaluating meets your specific backup needs.

Regionality: Some geographic areas have data sovereignty and data residency requirements, so encryption keys may be managed differently based on the regional requirements.

Governance: Some data may be governed by data protection regulations, and a company’s encryption and encryption key management policies may need to meet specific regulatory compliance needs.

How to Buy Encryption Key Management Software

Requirements Gathering (RFI/RFP) for Encryption Key Management Software

Gather your company’s specific encryption key management requirements, including if you need to manage your encryption keys on-premises, with a centralized cloud key management offering, or using an infrastructure-specific encryption key management service. It is important to determine what kind of interoperability you require. Also, consider the scale at which you need keys deployed and managed and the availability you seek. Discuss your backup needs. Authentication and access control functionality is also important. And determine which geographic areas your business needs are, and be sure to speak with vendors about these requirements.

Compare Encryption Key Management Software Products

Create a long list

The long list should include a list of providers that meet your basic interoperability, hosting, scale, regionality, and functionality requirements. Companies can identify products by using software review sites like G2.com to review what users of those solutions like and dislike, along with rankings on six satisfaction metrics.

Create a short list

Shorten your long list by identifying must-have functionality. Factors to consider at this stage include integrations, price, and whether the solution meets your regulatory requirements.

Conduct demos

When conducting demos of each potential solution, it is important to ask questions about the user interface, the ease of use, and the skills required to operate the encryption key management solution. The company’s staff should be able to learn the functionality of the tool quickly to receive the fastest return on investment.

Selection of Encryption Key Management Software

Choose a selection team

The selection team should include employees using the encryption key management tool in their daily duties and understand the use case. These would typically be colleagues from information security (Infosec) and information technology (IT) teams. Other parties from leadership and finance should also be included.

Negotiation

Security products such as encryption key management tools help companies manage risk. Knowing the cost of a breach or exposed keys to an organization can help your company understand the value these tools bring to your company. Understand what your budget is with this in mind.  

Final decision

Colleagues who work on defining and managing the company’s data security policies and programs are in the best position to decide which software solution fits the organization’s needs. These professionals will have the most experience with cryptography tools and can best evaluate the products.