HashiCorp Vault is a fantastic secrets manager, and the PKI secrets engine is one of the cleanest ways to issue short-lived certificates programmatically. TigerTrust does not replace Vault — it adds the lifecycle layer Vault was never designed to be: discovery, expiry alerts, compliance reporting, and multi-CA orchestration.
Vault's PKI engine is elegant for developers issuing short-lived certs from a role. It is not, and does not try to be, a certificate lifecycle platform. That is where TigerTrust fits.
Vault is exceptional at what it is designed for. This table is not an attack on Vault — it is a map of where the PKI engine ends and the CLM job begins.
| Capability | TigerTrust | HashiCorp Vault PKI Secrets Engine |
|---|---|---|
Internal PKI issuance (short-lived certs) Vault PKI is genuinely one of the cleanest issuance APIs | ||
K/V secrets, dynamic DB creds, transit encryption Keep Vault for these — TigerTrust is not a general secrets manager | ||
ACME protocol | ||
CRL & OCSP | ||
HSM-backed keys Vault HSM auto-unseal is Enterprise-only | ||
Certificate discovery outside the issuer | ||
Multi-channel expiry alerting | ||
Compliance evidence pack (SOC 2, PCI, HIPAA) | ||
Cross-CA policy enforcement | ||
Endpoint deployment orchestration |
Nobody rips out Vault to adopt TigerTrust. You keep Vault as an issuer and gain the lifecycle layer above it.
Point TigerTrust at your Vault PKI mount. Existing roles, policies, and issuance behaviour stay authoritative on the Vault side.
Scan networks, clouds, and Kubernetes clusters. Every certificate — Vault-issued or otherwise — enters one inventory.
Assign owners, connect Slack / PagerDuty / ServiceNow, enable the compliance evidence pack for your frameworks.
Add DigiCert, Sectigo, Let's Encrypt, private CAs, or ADCS as additional issuers. Policy routes each request to the appropriate CA.
No. Many teams keep Vault as an issuer and use TigerTrust as the CLM layer on top. TigerTrust can treat your Vault PKI mount as one of many upstream CAs, inheriting whatever roles and policies you already have.
Vault Enterprise adds performance replication, HSM auto-unseal, namespaces, and other secrets-management capabilities. It does not turn Vault into a certificate lifecycle platform. Discovery, expiry alerting, compliance reporting, and multi-CA orchestration remain out of scope.
That is exactly the visibility gap TigerTrust closes. Discovery scans networks, cloud providers, Kubernetes clusters, and load balancers to inventory certificates regardless of who issued them — Vault, DigiCert, Let's Encrypt, AWS Private CA, or a shadow OpenSSL command run three years ago.
No. TigerTrust exposes a full API and CLI. Your SREs can keep pulling certificates programmatically — via Vault or via TigerTrust — while security and compliance teams get the dashboard, reporting, and alerting workflows they need.
TigerTrust is deliberately focused on machine identity and certificate lifecycle — not a general secrets manager. If you need K/V secrets, dynamic database credentials, or transit encryption, keep using Vault. TigerTrust complements Vault rather than replacing it.
Yes. TigerTrust supports fully-managed cloud, single-tenant hosted, and self-managed / air-gapped on-premise deployments, including customer-controlled HSMs.
“Vault issued short-lived certs beautifully. It never told us what was in the estate, what was expiring, or how to prove compliance to auditors.”
Vault stays authoritative for issuance and secrets. TigerTrust ships the discovery, alerting, compliance, and Kubernetes surface that lives above it.
The other developer-first PKI tool teams often pair with an enterprise CLM layer above.
The cloud-native private CA teams evaluate alongside Vault for internal issuance.
The CLM product that treats Vault as one issuer among many and adds everything above it.
The Kubernetes-first CLM path — cert-manager, workload identity, and Vault in one plane.