Static Secrets
OpenBao provides a central store for your credentials – with versioning, lease management, and a full audit log. Secrets no longer need to live in Git repositories or ConfigMaps.
Secrets Management
Made in Germany
ayedo operates OpenBao for your secrets, certificates, and dynamic credentials – central, auditable, and part of your Software Delivery Platform. You use the APIs; operations and availability stay with us.






























Manage secrets securely
Our secrets management is based on OpenBao in the platform cluster – central secrets without in-house build-out, predictable instance costs, and developers without vault ops. ayedo handles day-2 including auto-unseal and Kubernetes integration.
Static Secrets
OpenBao provides a central store for your credentials – with versioning, lease management, and a full audit log. Secrets no longer need to live in Git repositories or ConfigMaps.
Dynamic Secrets
Database credentials, cloud IAM roles, and service accounts are created on demand, rotated automatically, and can be revoked at any time.
PKI & Certificates
An internal certificate authority issues certificates for mTLS, service mesh, and ingress – issuance and renewal are fully automated.
Encryption as a Service
The transit engine encrypts sensitive data at rest and in transit – without requiring you to build your own key management infrastructure.
Kubernetes Integration
The External Secrets Operator syncs your secrets into workload clusters – either as Kubernetes secrets or as mounted files.
EU Infrastructure
Your key material and secrets remain on European infrastructure – GDPR-compliant and independent of US cloud providers.
Pricing
Managed OpenBao is available as part of the ayedo platform – in the ayedo Cloud, on a dedicated cluster, or on your own infrastructure (BYOC/on-premises).
ayedo Cloud
€199.95/month per OpenBao instance
HA setup with auto-unseal
Kubernetes secrets sync (ESO)
Audit logging included
OIDC via ayedo ID
Operated in the central Platform Cluster
Dedicated
from €199.95/month per cluster
OpenBao in a dedicated Platform Cluster
Your own, fully isolated instance
Custom namespaces & policies
Disaster recovery between regions
Custom SLAs
BYOC / On-Premises
OpenBao in your cloud or on-premises
Optional HSM integration
Support for air-gapped environments
Enterprise support
Prepared for your compliance requirements
Custom SLAs
Compare with alternatives
Managed OpenBao on the ayedo platform provides sovereign secrets management on European infrastructure – cloud-agnostic and independent of any single cloud provider.
| Criterion | ayedo | AWS Secrets Manager |
|---|---|---|
| Jurisdiction | EU / GDPR-compliant | US / Cloud Act |
| Multi-cloud | Cloud-agnostic | AWS-only |
| Dynamic secrets | OpenBao engines | Limited |
| PKI | Built-in | ACM separate |
| Criterion | ayedo | Azure Key Vault |
|---|---|---|
| Vendor lock-in | Open ecosystem | Azure-focused |
| Kubernetes | Native operator / ESO | Azure-specific |
| On-premises / BYOC | Available | Cloud-first |
| Support | Personal, in German/English | Ticket system |
| Criterion | ayedo | GCP Secret Manager |
|---|---|---|
| Jurisdiction | EU hosting | US company |
| Encryption | Transit + KMS | Cloud KMS |
| Audit | Full audit log | Cloud Logging |
| Pricing transparency | Fixed per instance | Per secret/op |
Die ayedo Software Delivery Platform erfüllt die Anforderungen aktueller EU-Verordnungen. Von GDPR über NIS-2 bis DORA – designed für regulierte Branchen und kritische Infrastrukturen.
GDPR-konforme Datenverarbeitung
EU-Datenhaltung (Deutschland), Customer-Managed Keys (BYOK/BYOHSM), Verschlüsselung at rest/in transit. ISO 27001-zertifiziertes Datenschutz-Management. Mehr zur GDPR.
NIS-2-konformer Betrieb
24/7 Monitoring, Incident-Response, BCP/DR-Prozesse, Supply-Chain-Transparenz (SBOM). Mehr zu NIS-2.
DORA-ready für Finanzinstitute
IKT-Risikomanagement, dokumentierte Exit-Strategien, Drittpartei-Risiko-Management, TLPT-Readiness. Mehr zu DORA.
CRA-konforme Software Supply Chain
SBOM-Generation, CVE-Scanning, signierte Container-Images, GitOps-basierte Audit-Trails. Mehr zum CRA.
Cloud Sovereignty Framework
EU-basierte Operations, offene Standards, Exit-Fähigkeit ohne Lock-in. Mehr zum Framework.
Data Act-konforme Portabilität
Offene APIs, standardisierte Formate, vollständige Exit-Runbooks. Mehr zum Data Act.
Integrierte Compliance-Roadmap
Wie ayedo GDPR, NIS-2, DORA, CRA, Data Act und ISO 27001/9001 systematisch adressiert. Zur Übersicht.
Part of the Software Delivery Platform
OpenBao is a core pillar for Identity, Code Repository, Delivery, and all Managed Apps – because secrets do not belong in Git repositories.
Identity
Access to OpenBao is provided via ayedo ID or your dedicated Keycloak – without additional local user accounts.
Managed Kubernetes
Your secrets are synced automatically into your workload clusters – no manual copying required.
Delivery
Argo CD pulls secrets directly from OpenBao – so no credentials end up in your Git repositories.
OpenBao App
You can find the technical specification and block reference on the OpenBao managed app page.
Excellent performance and maximum uptime - that's what we wake up for. And sometimes even in the middle of the night.
100+ clusters
We operate more than 100 Kubernetes clusters in production for our customers.
300+ databases
We operate, monitor, and protect more than 300 production databases.
1 Petabyte Object-Storage
We operate one petabyte of object storage for backups, artifacts, and application data.
100 million timeseries
Our monitoring systems ingest 4 million datapoints per second.
38.000+ Logs
Our collectors capture logs continuously and store them GDPR-compliant — over 100 billion entries per month.
5.000+ Backups
We write more than 5,000 backups every day to encrypted long-term storage — about 150 terabytes of backup volume per month.
270 million end users
More than 9 million end users use software we operate every day, on the internet or on-premises.
99,99% Uptime
Our managed services are unavailable for less than one hour per year on average.
MTTD < 5 minutes
Our alerting typically detects faults and outages within a few minutes.