TigerTrust vs HashiCorp Vault

The CLM layer around your Vault PKI.

HashiCorp Vault is a fantastic secrets manager, and the PKI secrets engine is one of the cleanest ways to issue short-lived certificates programmatically. TigerTrust does not replace Vault — it adds the lifecycle layer Vault was never designed to be: discovery, expiry alerts, compliance reporting, and multi-CA orchestration.

Why teams add TigerTrust

Keep Vault. Add the CLM layer above it.

Vault's PKI engine is elegant for developers issuing short-lived certs from a role. It is not, and does not try to be, a certificate lifecycle platform. That is where TigerTrust fits.

Expiry alerts and owner routing
Multi-channel notifications (Slack, PagerDuty, email, ServiceNow) with owner assignment and escalation — Vault leaves this to you.
Discovery beyond Vault
Network scanning, cloud discovery, Kubernetes discovery, and CT-log correlation surface certificates Vault never issued.
Compliance evidence pack
Prebuilt SOC 2, PCI, HIPAA, and weak-key reports. Audit-ready evidence exports without log-scraping Vault audit devices.
Multi-CA orchestration
Vault PKI as one issuer among many. DigiCert, Sectigo, Entrust, Let's Encrypt, ADCS, and private CAs all managed under one policy.
Where the gap is

Vault does secrets brilliantly. CLM is a different job.

Without HashiCorp Vault
  • No built-in expiry alerts — you build monitoring yourself
  • No discovery of certificates issued outside Vault
  • No compliance reporting pack (SOC 2, PCI, HIPAA)
  • Policy scoped per role; no cross-issuer policy plane
  • Renewal is client-driven — no orchestration or deployment layer
With TigerTrust
  • Multi-channel expiry alerting with owner routing built in
  • Discovery across networks, clouds, and Kubernetes clusters
  • Prebuilt compliance evidence packs, audit-ready exports
  • Cross-issuer policy enforcement — Vault, public CAs, private CAs
  • Orchestrated renewal and endpoint deployment out of the box

Capability comparison, complementary not competing.

Vault is exceptional at what it is designed for. This table is not an attack on Vault — it is a map of where the PKI engine ends and the CLM job begins.

CapabilityTigerTrustHashiCorp Vault PKI Secrets Engine
Internal PKI issuance (short-lived certs)
Vault PKI is genuinely one of the cleanest issuance APIs
K/V secrets, dynamic DB creds, transit encryption
Keep Vault for these — TigerTrust is not a general secrets manager
ACME protocol
CRL & OCSP
HSM-backed keys
Vault HSM auto-unseal is Enterprise-only
Certificate discovery outside the issuer
Multi-channel expiry alerting
Compliance evidence pack (SOC 2, PCI, HIPAA)
Cross-CA policy enforcement
Endpoint deployment orchestration

Add TigerTrust on top of Vault.

Nobody rips out Vault to adopt TigerTrust. You keep Vault as an issuer and gain the lifecycle layer above it.

01

Connect Vault as an issuer

Point TigerTrust at your Vault PKI mount. Existing roles, policies, and issuance behaviour stay authoritative on the Vault side.

02

Turn on discovery

Scan networks, clouds, and Kubernetes clusters. Every certificate — Vault-issued or otherwise — enters one inventory.

03

Wire up alerting and reporting

Assign owners, connect Slack / PagerDuty / ServiceNow, enable the compliance evidence pack for your frameworks.

04

Extend to other CAs

Add DigiCert, Sectigo, Let's Encrypt, private CAs, or ADCS as additional issuers. Policy routes each request to the appropriate CA.

Frequently asked questions

Do I have to rip out Vault to use TigerTrust?

No. Many teams keep Vault as an issuer and use TigerTrust as the CLM layer on top. TigerTrust can treat your Vault PKI mount as one of many upstream CAs, inheriting whatever roles and policies you already have.

Vault Enterprise adds more features. Isn't that enough?

Vault Enterprise adds performance replication, HSM auto-unseal, namespaces, and other secrets-management capabilities. It does not turn Vault into a certificate lifecycle platform. Discovery, expiry alerting, compliance reporting, and multi-CA orchestration remain out of scope.

What about certificates we issued outside Vault?

That is exactly the visibility gap TigerTrust closes. Discovery scans networks, cloud providers, Kubernetes clusters, and load balancers to inventory certificates regardless of who issued them — Vault, DigiCert, Let's Encrypt, AWS Private CA, or a shadow OpenSSL command run three years ago.

Our SREs love the Vault CLI. Will they lose that?

No. TigerTrust exposes a full API and CLI. Your SREs can keep pulling certificates programmatically — via Vault or via TigerTrust — while security and compliance teams get the dashboard, reporting, and alerting workflows they need.

How does TigerTrust handle secrets other than certificates?

TigerTrust is deliberately focused on machine identity and certificate lifecycle — not a general secrets manager. If you need K/V secrets, dynamic database credentials, or transit encryption, keep using Vault. TigerTrust complements Vault rather than replacing it.

Can we deploy TigerTrust on-premise?

Yes. TigerTrust supports fully-managed cloud, single-tenant hosted, and self-managed / air-gapped on-premise deployments, including customer-controlled HSMs.

Case study
Cloud-native · High-growth SaaS

Kept Vault PKI authoritative, added the CLM layer around it.

Vault issued short-lived certs beautifully. It never told us what was in the estate, what was expiring, or how to prove compliance to auditors.
Head of Platform Engineering
3 wk
Time to unified inventory
410K
Certificates discovered outside Vault
100%
SOC 2 evidence automated
Integrations

The enterprise CLM layer around your Vault PKI.

Vault stays authoritative for issuance and secrets. TigerTrust ships the discovery, alerting, compliance, and Kubernetes surface that lives above it.

HashiCorp Vault PKI
CA
Kubernetes cert-manager
DevOps
Slack
Alerts
PagerDuty
Alerts
ServiceNow
ITSM
Splunk
SIEM
DigiCert
CA
Microsoft ADCS
CA
AWS / Azure / GCP
Discovery

Keep Vault. Add the CLM.