Secrets Management
Made in Germany

ayedo operates OpenBao for your secrets, certificates, and dynamic credentials – central, auditable, and part of your Software Delivery Platform. You use the APIs; operations and availability stay with us.

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Manage secrets securely

Our secrets management is based on OpenBao in the platform cluster – central secrets without in-house build-out, predictable instance costs, and developers without vault ops. ayedo handles day-2 including auto-unseal and Kubernetes integration.

Static Secrets

API keys & passwords

OpenBao provides a central store for your credentials – with versioning, lease management, and a full audit log. Secrets no longer need to live in Git repositories or ConfigMaps.

KVCredentialsAudit

Dynamic Secrets

Short-lived access

Database credentials, cloud IAM roles, and service accounts are created on demand, rotated automatically, and can be revoked at any time.

DynamicRotationIAM

PKI & Certificates

TLS as a service

An internal certificate authority issues certificates for mTLS, service mesh, and ingress – issuance and renewal are fully automated.

PKITLSmTLS

Encryption as a Service

Transit engine

The transit engine encrypts sensitive data at rest and in transit – without requiring you to build your own key management infrastructure.

TransitEncryptionKMS

Kubernetes Integration

Native for Kubernetes

The External Secrets Operator syncs your secrets into workload clusters – either as Kubernetes secrets or as mounted files.

K8sESOOperator

EU Infrastructure

Sovereign hosting

Your key material and secrets remain on European infrastructure – GDPR-compliant and independent of US cloud providers.

EUGDPRSovereignty

Pricing

Managed OpenBao is available as part of the ayedo platform – in the ayedo Cloud, on a dedicated cluster, or on your own infrastructure (BYOC/on-premises).

Dedicated

Dedicated cluster · Single-tenant
  • from €199.95/month per cluster

  • OpenBao in a dedicated Platform Cluster

  • Your own, fully isolated instance

  • Custom namespaces & policies

  • Disaster recovery between regions

  • Custom SLAs

BYOC / On-Premises

On your infrastructure
  • OpenBao in your cloud or on-premises

  • Optional HSM integration

  • Support for air-gapped environments

  • Enterprise support

  • Prepared for your compliance requirements

  • Custom SLAs

Compare with alternatives

Managed OpenBao on the ayedo platform provides sovereign secrets management on European infrastructure – cloud-agnostic and independent of any single cloud provider.

vs. AWS Secrets Manager

Criterion ayedo AWS Secrets Manager
Jurisdiction EU / GDPR-compliant US / Cloud Act
Multi-cloud Cloud-agnostic AWS-only
Dynamic secrets OpenBao engines Limited
PKI Built-in ACM separate

vs. Azure Key Vault

Criterion ayedo Azure Key Vault
Vendor lock-in Open ecosystem Azure-focused
Kubernetes Native operator / ESO Azure-specific
On-premises / BYOC Available Cloud-first
Support Personal, in German/English Ticket system

vs. GCP Secret Manager

Criterion ayedo GCP Secret Manager
Jurisdiction EU hosting US company
Encryption Transit + KMS Cloud KMS
Audit Full audit log Cloud Logging
Pricing transparency Fixed per instance Per secret/op

Compliance & regulatorische Anforderungen

Die ayedo Software Delivery Platform erfüllt die Anforderungen aktueller EU-Verordnungen. Von GDPR über NIS-2 bis DORA – designed für regulierte Branchen und kritische Infrastrukturen.

GDPR-konforme Datenverarbeitung

Privacy by Design & Default.

EU-Datenhaltung (Deutschland), Customer-Managed Keys (BYOK/BYOHSM), Verschlüsselung at rest/in transit. ISO 27001-zertifiziertes Datenschutz-Management. Mehr zur GDPR.

NIS-2-konformer Betrieb

Resilienz für kritische Infrastrukturen.

24/7 Monitoring, Incident-Response, BCP/DR-Prozesse, Supply-Chain-Transparenz (SBOM). Mehr zu NIS-2.

DORA-ready für Finanzinstitute

IKT-Resilienz nach Maß.

IKT-Risikomanagement, dokumentierte Exit-Strategien, Drittpartei-Risiko-Management, TLPT-Readiness. Mehr zu DORA.

CRA-konforme Software Supply Chain

Security by Design über den gesamten Lifecycle.

SBOM-Generation, CVE-Scanning, signierte Container-Images, GitOps-basierte Audit-Trails. Mehr zum CRA.

Cloud Sovereignty Framework

Digitale Souveränität messbar gemacht.

EU-basierte Operations, offene Standards, Exit-Fähigkeit ohne Lock-in. Mehr zum Framework.

Data Act-konforme Portabilität

Switching ohne Hürden.

Offene APIs, standardisierte Formate, vollständige Exit-Runbooks. Mehr zum Data Act.

Integrierte Compliance-Roadmap

Ganzheitlicher Ansatz.

Wie ayedo GDPR, NIS-2, DORA, CRA, Data Act und ISO 27001/9001 systematisch adressiert. Zur Übersicht.

Part of the Software Delivery Platform

OpenBao is a core pillar for Identity, Code Repository, Delivery, and all Managed Apps – because secrets do not belong in Git repositories.

Identity

OIDC access

Access to OpenBao is provided via ayedo ID or your dedicated Keycloak – without additional local user accounts.

OIDCKeycloakSSO

Managed Kubernetes

Secrets for workloads

Your secrets are synced automatically into your workload clusters – no manual copying required.

KubernetesESOSync

Delivery

GitOps-safe deployments

Argo CD pulls secrets directly from OpenBao – so no credentials end up in your Git repositories.

ArgoCDGitOpsSecurity

OpenBao App

Managed app details

You can find the technical specification and block reference on the OpenBao managed app page.

OpenBaoManaged App

You build it. We run it.

Excellent performance and maximum uptime - that's what we wake up for. And sometimes even in the middle of the night.

100+ clusters

under Management

We operate more than 100 Kubernetes clusters in production for our customers.

300+ databases

under Management

We operate, monitor, and protect more than 300 production databases.

1 Petabyte Object-Storage

under Management

We operate one petabyte of object storage for backups, artifacts, and application data.

100 million timeseries

on average

Our monitoring systems ingest 4 million datapoints per second.

38.000+ Logs

per second

Our collectors capture logs continuously and store them GDPR-compliant — over 100 billion entries per month.

5.000+ Backups

per day

We write more than 5,000 backups every day to encrypted long-term storage — about 150 terabytes of backup volume per month.

270 million end users

per month

More than 9 million end users use software we operate every day, on the internet or on-premises.

99,99% Uptime

annual average

Our managed services are unavailable for less than one hour per year on average.

MTTD < 5 minutes

on average

Our alerting typically detects faults and outages within a few minutes.