Listing Thumbnail

    Infisical Secret Management

     Info
    Sold by: Infisical 
    Infisical is the leading platform for developers to securely manage application configuration and secrets across their team and infrastructure. Used by Fortune 500 enterprises, international governments, and fastest-growing startups. With Infisical, you can save time for your engineering teams and enhance organization-wide security posture.
    4.5

    Overview

    Infisical is the leading open-source secrets management platform designed to securely store, manage, and synchronize application configuration and sensitive information like API keys, database credentials, and environment variables across engineering teams and infrastructure.

    Infisical is available both through Infisical Cloud (a hosted SaaS product) as well as Infisical Self-hosted (self-managed on-prem product). Through SOC2 compliance, continuous penetration testing, enterprise uptime guarantee, and support SLAs, Infisical is able to satisfy the hardest security and reliability requirements of global enterprises. As a result, Infisical supports a myriad of Fortune 500 corporations, governmental institutions, as well as the fastest-growing startups in the world.

    Infisical's value comes from enabling operational advantage of engineering organizations as well as enhancing organization-wide security posture. To achieve that, Infisical offers a full-fledged set of tools for managing secrets in production environments, efficiently injecting secrets into CI/CD pipelines, enabling local development workflows, preventing secrets leaks, ensuring secure secret sharing, and more!

    In addition, Infisical comes with 50+ integration across leading developer and infrastructure tools (e.g., AWS, GitHub Actions, GitLab CI/CD, Jenkins, Kubernetes, Terraform, Ansible, Docker), as well as frameworks such as Next.js, Express, Django, among others.

    We recommend speaking to Infisical before purchasing to ensure the best experience. Please contact sales@infisical.com  for a private offer.

    Highlights

    • Unified secret management platform for developers with additional secret scanning and secret sharing capabilities.
    • Integrates with all leading developer and infrastructure tools, including Kubernetes, Jenkins, AWS, GitHub Actions, and GitLab CI/CD.
    • Available both through a self-hosted on-prem installation as well as a managed Infisical Cloud offering.

    Details

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Infisical Secret Management

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Identity
    Identities are represented by either human or machine users.
    $1,000.00

    Vendor refund policy

    All fees are non-cancellable and non-refundable except as required by law.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Submit a ticket via support@infisical.com  or your dedicated support engineer.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    100
    In Monitoring
    Top
    50
    In Infrastructure as Code, Continuous Integration and Continuous Delivery

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    18 reviews
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Secret Storage and Management
    Securely stores, manages, and synchronizes application configuration and sensitive information including API keys, database credentials, and environment variables across engineering teams and infrastructure.
    CI/CD Pipeline Integration
    Efficiently injects secrets into CI/CD pipelines with integrations for GitHub Actions, GitLab CI/CD, Jenkins, and other leading developer tools.
    Multi-Platform Deployment Options
    Available as both self-hosted on-premises installation and managed cloud-based SaaS offering to accommodate different deployment requirements.
    Extensive Third-Party Integrations
    Supports 50+ integrations across infrastructure tools such as Kubernetes, AWS, Terraform, Ansible, Docker and frameworks including Next.js, Express, and Django.
    Enterprise Security Compliance
    Maintains SOC2 compliance, undergoes continuous penetration testing, and provides enterprise uptime guarantees with support SLAs to meet security and reliability requirements.
    Centralized Secrets Management
    Centrally secures, rotates, and manages secrets across multi-cloud and hybrid environments with a unified view across multiple AWS accounts and AWS Secrets Manager instances.
    Multi-Platform Integration
    Offers REST APIs and integrates with a wide range of DevOps tools, container platforms, vulnerability scanners, RPA, and automation tools for credential delivery.
    Secrets Rotation and Lifecycle Management
    Automatically rotates secrets in AWS Secrets Manager and across enterprise environments without requiring changes to developer workflows or applications.
    Audit and Access Control
    Provides centralized control and comprehensive auditing of how applications, DevOps tools, and automation platforms authenticate and access sensitive resources including databases and cloud environments.
    Enterprise-Scale Architecture
    Designed to support massive scalability with data sovereignty requirements for large global enterprises and eliminates vault sprawl across distributed environments.
    Secrets Management and Rotation
    Centrally manages and rotates credentials across hybrid and multi-cloud environments with automated lifecycle management
    Privileged Access Management
    Provides just-in-time, least-privilege access with intent-aware control that evaluates requested actions before granting access and issues task-scoped, short-lived credentials
    Multi-Vault Governance
    Unifies visibility and control across AWS and third-party vaults through a single policy and audit framework
    Cryptographic Security
    FIPS 140-3 validated platform powered by Distributed Fragments Cryptography (DFC) and zero-knowledge architecture that ensures encryption keys and secrets are never fully assembled or accessible
    AI Agent Identity Security
    Secures autonomous agents with ephemeral, policy-bound access without embedding credentials in code, prompts, or workflows, with continuous execution inspection and audit trails

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.5
    18 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    67%
    33%
    0%
    0%
    0%
    4 AWS reviews
    |
    14 external reviews
    External reviews are from G2  and PeerSpot .
    Daniel Odeh

    Centralized secret management has streamlined daily operations but still needs automation features

    Reviewed on Jul 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We use Infisical to manage secrets day-to-day, currently hosting it on our machines in our offices. Since secrets are something very vital to us, we need somewhere to store secrets securely, and that's why we are using it. Applications need secrets. Applications have APIs and certificates, so day-to-day we use the service to get our secrets and to rotate secrets. That's what we use it for. We use Infisical internally in my company.

    What is most valuable?

    I think the core functionality or feature of saving secrets is the most valuable aspect of Infisical. It also has the organogram of how it was designed, where one could have multiple organizations. In each organization, you could have different projects, and in these projects, you could have different environments. This gives it the flexibility to have as many secrets as you could have for different organizations if you're working on a large or enterprise company. It also helps with sharing secrets. In our company, we use Kubernetes, so one can fetch these secrets from Infisical and then put them into the Kubernetes cluster. That feature is really nice. Additionally, one could rotate the secrets because you're not expected to store the same secret for a very long time, making it dynamic. It also has an audit trail of what is happening with the secret, including who changed what at what time. The core functionality for me is really what makes it amazing.

    Real-time monitoring and alerts with Infisical do help improve our response times to incidents. We've not really had any incidents at all, but it really helps with alerts and monitoring, of course.

    Since starting to use Infisical in my company, the overall positive impact includes saving time for developers who might otherwise try to save secrets somewhere. When someone comes in, you need to share the secret with them. Infisical has saved engineering time where a developer or someone needing a secret, certificate, or API key knows there is a specific place to go. Everything is organized in a hierarchy.

    What needs improvement?

    Unfortunately, we don't use Infisical's automated key rotation. For now, we rotate the secrets ourselves.

    We've not tried to improve Infisical, so I don't know if there are enhancements planned. We aim to explore using it with AI models and HCP server features implementation with Infisical. We consider having an agent that generates secrets instead of doing it manually. If a file or a secret is needed, the agent might generate it for us based on a specified pattern for the kind of secrets we want, including the length. This would be efficient, as we want to save engineering time. For example, with certificate keys already generated, we currently have to manually copy and put them into the Infisical UI. If an agent could handle that for us, it would be great.

    For how long have I used the solution?

    For close to three years now, I've been working with Infisical.

    What do I think about the stability of the solution?

    My evaluation of the reliability and stability of Infisical thus far is positive. It has been reliable and stable for us, and we've not experienced issues scaling or moving to a new image. It does not require many resources. Since we haven't had high resource utilization from end users, we can't determine its full reliability for extensive demands, such as if 20,000 or 50,000 people try to access our instance. Right now, we are quite small, and it's serving our needs without any downtime. It has been highly available since we brought it up. So, for our use case, it's acceptable.

    What do I think about the scalability of the solution?

    Infisical is currently scalable for us because of its design in the Kubernetes cluster. However, I can't give it a 100% rating for scalability since, as a startup, we've not had a large number of users putting it under heavy load, nor have we scaled it to more than two or three pods or instances. For our current use case, it's quite okay since we don't have many engineers, and it's heavily utilized by the Kubernetes cluster, resulting in considerable resource utilization.

    How are customer service and support?

    We don't have access to their technical support or customer service.

    I use the documentation available on GitHub and their website for Infisical. The documentation is great, and we follow those resources. When we encounter issues with the services, we often use AI to help resolve those issues, so we've not really needed additional support.

    Which solution did I use previously and why did I switch?

    Before Infisical, I was using HashiCorp Vault for the same use cases. However, the company tried to save on costs due to the license for HashiCorp Vault, which is why we moved to open source.

    How was the initial setup?

    The initial setup process for Infisical involved using their documentation and Kubernetes. They offer a Kubernetes manifest that you can utilize, making it quite easy to set up. Everything is already packaged in the service or image for Infisical, including PostgreSQL, and you just need an external database. We had it up and running in a day, so it was not a difficult task.

    What about the implementation team?

    I participated in the initial setup of Infisical as the lead engineer.

    Which other solutions did I evaluate?

    I was actually the one that kind of pushed for Infisical. When I conducted research, I found it was the only open-source solution that stood out. There are other open-source options, but I can't really remember their names. To harness the full capabilities of those services, however, you often need to pay. My company is a startup, so they're primarily focused on cost-saving, which is why I advocated for Infisical.

    What other advice do I have?

    I would evaluate Infisical's integration with our existing workflows as great. I think systems have to be simple and just do one thing. It really integrates well because we just have to put the secret variable or whatever it is in our code, and since the Kubernetes operator for Infisical is in our cluster, it knows where to get our secrets. I think it really fits well for our use case, actually.

    The capability of Infisical to manage secrets across our cloud and on-premises environments is primarily important for us. It's very key because if anyone has your secret, then they could access different systems in an organization. The capabilities in Infisical are really nice, featuring great functionality with what's already done there. It's very, very important at this point. We really can't do without it because of how vital it is for us in managing our secrets. We're not just talking about secrets; we are also discussing certificates, API keys, or anything that shouldn't be exposed to the public. It has this access control where you could determine who can see what and who shouldn't see certain information. At this point in time, it's one of our primary services that we use in the company and we can't do without it.

    We have seen a reduction in human errors with Infisical's customizable access policies. The policy helps, but we have encountered issues with newbies who join the company and haven't fully onboarded. This results in developers trying to push secrets to just the Git repository. Those cases are not really an Infisical issue, but we're trying to see how to ensure developers don't expose secrets. For now, it's manageable, but we could still have edge cases where someone doesn't know what's happening and exposes a secret to the repository. Unfortunately, we don't have a secret scanning feature in our Bitbucket repository, which is the only edge case. Otherwise, the policies are already in place, and they really help.

    I would rate this product a 7 overall.

    reviewer2870445

    Centralized secret management has streamlined deployments and improves team collaboration

    Reviewed on Jul 09, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have been using Infisical consistently for the past couple of years in my current company. The main use case of Infisical is to manage our secrets. We use it to properly manage application secrets and environmental variables across development, staging, and production, replacing hard-coded secrets and .env files with a centralized, secure secrets manager for .NET, Node.js, or AWS workloads. Our main use case is secure secret management, environmental variable management, and syncing it with any other Vercel or cloud deployment that we use.

    How we use it depends on the particular applications in the first place. Technically, we use Infisical to securely manage secrets for our AWS-hosted applications. During CI/CD deployments, our GitHub Actions pipelines retrieve environment-specific secrets such as database connection strings, JWT signing keys, and third-party API credentials like Knovo, Twilio, or Resend from Infisical and inject them into the applications at deploy time. This keeps secrets out of the codebase and avoids storing them in repository or pipeline variables.

    For AWS Lambda specifically, our AWS Lambda functions retrieve their configurations and secrets from Infisical during deployment. This allows us to maintain separate secrets for development, staging, and production while ensuring sensitive values such as database credentials and API keys are never committed to source control.

    What is most valuable?

    There are a bunch of features that we are using right now. The best features are centralized secret management, environmental separation, and secret versioning.

    Centralized secret management makes day-to-day development much easier because everyone works from a single source of truth. Developers do not need to request secrets from teammates or keep local .env files in sync because we do not push our .env files to our GitHub. We manage separate secrets for development, staging, and production, and access is controlled through roles, so each person only sees what they need. When it comes to secret versioning, it is useful when rotating credentials or updating configuration. If a new secret causes an issue after deployment, we can quickly see what changed and roll back to a previous version instead of manually tracking all values.

    One of the best features I find very useful is that it is hosted and everyone who has access can easily access it and update it accordingly. Infisical has significantly improved our security posture by giving us a centralized and controlled way to manage application secrets. Previously, managing environmental variables across multiple services and environments became difficult, especially when teams needed to share or rotate credentials.

    From a productivity perspective, developers spend less time requesting, locating, or manually updating secrets. New team members can be onboarded faster because access can be granted through proper permissions instead of sharing sensitive values manually. Infisical has improved collaboration between development and operations teams by providing a consistent workflow for managing secrets across local development, staging, production, and CI/CD deployments. Overall, it reduces the risk of accidental secret exposure while making deployments more reliable and repeatable.

    What needs improvement?

    Infisical is already a strong solution for centralized secret management, but there are a few areas where it could be improved. The user experience could be made even more intuitive, especially for teams that are new to secret management platforms because more guidance steps or secret and environment migration tools would help teams onboard faster. Improving documentation with more real-world examples for different architectures such as AWS Lambda and Kubernetes, .NET applications, and multi-account cloud setups would help teams adapt best practices faster. Overall, the product direction is strong and continued improvements around automation, integration, and enterprise governance features would make it even more valuable.

    One area that could be improved further is automation around the full secret lifecycle. Making secret rotation more seamless with cloud services, databases, and third-party providers would reduce manual setups and improve security.

    For how long have I used the solution?

    I have been using Infisical consistently for the past couple of years in my current company.

    What do I think about the stability of the solution?

    We have not encountered any significant stability issues because it has been pretty stable throughout the development that we have implemented so far. The platform has been stable and reliable for our needs. We have not experienced any significant downtime or reliability issues that have impacted our development or deployment workflows because once they have been loaded, they perform their job well. The platform has performed well for managing secrets across environments and the availability has been pretty consistent and reliable in our experience.

    The main reliability benefit is that it provides a centralized and predictable way to access secrets rather than relying on manually maintained configuration files or shared credentials. It is pretty stable in my opinion because we have not encountered any downtime.

    What do I think about the scalability of the solution?

    Infisical has been able to support our current needs and provides a scalable approach as our applications and environments grow. The ability to organize secrets by project, environment, and access permissions makes it easier to manage increasing complexity without adding significant operational overhead. We can manage multiple projects as well. As our usage grows, areas such as advanced automation, deep integration, and more granular governance capabilities will become increasingly important, but overall, Infisical provides a solid foundation for scaling secret management.

    How are customer service and support?

    We have not encountered any situation where we have needed to cooperate with their customer service support because we have not run into any trouble that we should refer to their customer support. The documentation and available resources have been very useful for resolving common issues independently. When dealing with more advanced scenarios, having access to knowledgeable support helps reduce the time needed to troubleshoot those issues.

    Which solution did I use previously and why did I switch?

    Previously, we used other solutions, but as the number of applications and environments grew, managing secrets consistently became more challenging. This is the main reason we moved to Infisical to have a centralized solution with better access control, auditing, versioning, and developer workflow. It simplified secret management across development, staging, and production while reducing the risk of secrets being stored or shared incorrectly.

    How was the initial setup?

    Pricing and the licensing model were straightforward and easy to understand. The setup cost was relatively low because Infisical does not require significant infrastructure changes. We were able to integrate it into our existing workflows without major overhead. The main value comes from reducing the operational effort around managing secrets, improving security practices, and making deployments more consistent. The licensing model provides flexibility as teams and usage grow, although continued improvements around enterprise-level cost visibility and usage insights would make planning even easier.

    What about the implementation team?

    We use AWS as our primary cloud provider because Infisical fits well into our AWS-based workflows by helping us securely manage application secrets and environmental configurations across all our environments.

    We did not purchase Infisical through the AWS Marketplace. We use Infisical as a separate service and integrate it with our AWS workloads through our existing development and deployment workflows. We have a separate team to manage them. We use Infisical as a separate service and integrated it with our AWS workloads.

    What was our ROI?

    We have seen a positive return on investment, mainly through improved productivity, reduced operational overhead, and stronger practices. We have not measured a direct cost saving in terms of reduced headcount, but the main benefit has been time savings and reduced manual effort. The best benefit is that we do not have to share our .env files throughout the team. Developers spend less time requesting, sharing, and troubleshooting environment secrets because everything is centrally managed with controlled access. Setting up new environments and onboarding new team members is also faster because the required secrets and permissions are already structured well.

    What's my experience with pricing, setup cost, and licensing?

    We have a separate team that manages the resources with the outcome. Pricing and the licensing model were straightforward and easy to understand. The setup cost was relatively low because Infisical does not require significant infrastructure changes. We were able to integrate it into our existing workflows without major overhead. The main value comes from reducing the operational effort around managing secrets, improving security practices, and making deployments more consistent.

    Which other solutions did I evaluate?

    We use Infisical through a public cloud deployment model because it allows us to leverage a managed service while benefiting from scalability, availability, and reduced operational overhead. It integrates well with our cloud-based development and deployment workflows, allowing teams to securely manage secrets across different environments without maintaining additional infrastructure.

    In the initial stages, we evaluated a couple of alternatives before choosing Infisical. We looked at options such as AWS Secrets Manager since we rely most on AWS, and HashiCorp Vault and other cloud-based secret management solutions. The main considerations were security, ease of integration, developer experience, operational overhead, and how well the solution would fit into our existing AWS and CI/CD workflows.

    What other advice do I have?

    Infisical is a great tool if you are looking for a tool to manage secrets because the amount of features that Infisical provides and the amount of reliability and shareable resources make it a source of truth and make it easy for teammates to manage secrets. It is very easy to use and it is a lifesaver when you are working in the software development lifecycle.

    I think anyone who is asking whether to shift to Infisical would find that it is the best option if they are looking for something to manage secrets. Infisical is a great tool to manage all your secrets and rather than just a tool, I think it is a lifesaver that people can use to make their software development much easier, especially when they are using it with the proper team. Wherever I go, whenever I need to manage my secrets, I would definitely go with Infisical. I would rate this product a nine out of ten.

    Accounting

    Great State of the Art solution

    Reviewed on Jul 09, 2026
    Review provided by G2
    What do you like best about the product?
    State of the Art Deployment and upgrade process. Clean UI. Developer focused integrations
    What do you dislike about the product?
    Occasional smaller bugs, but responses are rapid and corrective actions are transparent.
    What problems is the product solving and how is that benefiting you?
    We needed a state of the Art replacement of our former Secret management Solution and found it with Infisical.
    Financial Services

    Infisical Streamlines Secret Management with Sync, Kubernetes Delivery, and Audit History

    Reviewed on Jul 08, 2026
    Review provided by G2
    What do you like best about the product?
    I like Infisical because it combines managed secret synchronization, a Kubernetes operator for seamless secret delivery, comprehensive audit history for compliance and visibility, and automatic secret rotation to reduce operational overhead while improving security.
    What do you dislike about the product?
    It doesn’t have the features I need yet.
    What problems is the product solving and how is that benefiting you?
    It helps us handle secret rotation, RBAC for both teams and individual users who need access to secrets, compliance requirements around secrets, and local use of secrets during development.
    Government Administration

    Infisical: Quick Setup, Intuitive Secrets & Certificate Management, and Excellent Support

    Reviewed on Jul 06, 2026
    Review provided by G2
    What do you like best about the product?
    From the very first stages of evaluating a secrets management platform, Infisical made a strong impression. During the initial research phase, we received quick and clear answers to our questions, making it easy to get a solid understanding of the platform's capabilities and whether it would fit our organization's needs.

    When requesting a price quote for the enterprise version, our interaction with GTM/sales was smooth and professional. They took the time to understand our specific situation without resorting to typical sales pitches — just clear, straightforward communication.

    The technical side is equally convincing. Setting up secrets management turned out to be surprisingly quick and easy, even in a somewhat more complex environment. The same goes for certificate management: intuitively designed and free of unnecessary complexity, allowing us to become operational fast.

    In short: a platform that's not only technically solid, but where the people behind the product make a real difference too. A pleasant experience from start to finish.
    What do you dislike about the product?
    So far, nothing significant to report. The onboarding, secrets management setup, and certificate management have all gone smoothly, and the sales/support experience has been positive throughout.
    What problems is the product solving and how is that benefiting you?
    Until now, we haven't experienced any problems.
    View all reviews