Identity-based security · a YoctoIT presentation

HashiCorp Vault

Secrets, certificates and encryption managed from a single platform, with identity-based security: for people, machines and AI agents.

NOW AN IBM COMPANY Native synergy with IBM Concert, QRadar, Terraform, IBM Z and Power
July 2026 · YoctoIT presentation material for customers and partners
01 · The context

The secrets are everywhere. And it shows.

Passwords, API keys, tokens and certificates multiply with cloud, automation and AI agents. They end up in the code, in the pipelines, in shared sheets: every copy is an open door.

4,4 mln $
the global average cost of a data breach (source: IBM, Cost of a Data Breach 2025)
97%
of the organizations hit by AI-related incidents lacked adequate AI access controls (source: IBM, 2025)
47 days
the maximum lifetime of public TLS certificates by 2029 (CA/Browser Forum)

Where do the secrets live today?

Source code and repositories
CI/CD pipelines and automations
Environment variables and configuration files
Sheets, wikis and tickets
Team chats and personal notes
02 · The platform

One identity, one safe

Vault authenticates every person, machine, service or AI agent and decides what it can read, for how long and under which policies. Everything traced, everything revocable.

It centralizes

a single point to guard and distribute secrets to people, machines and AI agents

It automates

creation, consumption, expiry and rotation of the secrets with a single API

It controls

granular policies and a complete audit trail of every access

Identity-based authenticationLDAP and Active Directory · OIDC · Kubernetes · cloud IAM
Vault corepolicy engine · complete audit trail · one API for everything
KV
Database
PKI
Transit
Secret engines: the engines issuing and managing static and dynamic secrets, certificates and encryption
03 · Dynamic secrets

The best credential expires on its own

Instead of fixed, shared, never-rotated passwords, Vault issues ephemeral, dedicated, time-boxed credentials: for databases, cloud and services.

STEP 1

Request

The application shows up with its identity (Kubernetes, cloud IAM, AppRole): no passwords in the code.

STEP 2

Issuance

Vault creates on the fly a dedicated credential on the database or the cloud, with minimal permissions.

STEP 3

A short life

The credential has a TTL: it's valid only for the time the job needs.

STEP 4

Revocation

At expiry it revokes itself. In case of an incident, immediate, centralized revocation.

New in Vault 2.0: with Workload Identity Federation, Vault too talks to AWS, Azure and Google Cloud without static credentials (source: HashiCorp)
04 · PKI and certificates

Certificates that renew themselves

On-demand issuance

the PKI secret engine issues, renews and revokes certificates via API, including with the ACME protocol

Automatic rotation

the renewal becomes a workflow, not a date marked on the calendar

IBM Concert integration

discovery of the expiring certificates and end-to-end orchestrated renewal, with Vault as the engine

The race to shorter lifetimes

Oggi · up to 398 days
2026 · 200 days
2027 · 100 days
2029 · 47 days

Maximum lifetime of public TLS certificates (CA/Browser Forum)

Renewing by hand will no longer be an option: an automated PKI is needed.

05 · Encryption

The keys never leave the safe

Encryption as a service

the applications call the transit secret engine to encrypt and decrypt: the keys stay in Vault

Centralized key management

generation, rotation and versioning of the keys, including towards the clouds' KMS services

HSMs and enterprise requirements

HSM integration and advanced controls in the Enterprise edition, for regulated environments

Application

it sends the data to protect: it neither sees nor guards any key

Vault · transit engine

it encrypts and decrypts via API, with versioned, rotatable keys

Protected data

on databases, storage and backups only the encrypted data travels and rests

06 · Vault Radar

Find the secrets before someone else does

Vault Radar scans code repositories and collaboration tools looking for exposed or unmanaged credentials, and brings them back under control.

It discovers

it analyzes repositories, wikis and chats: every secret in the clear gets found and inventoried

Prioritizza

it ranks the findings by risk and context: first what's really exposed

It remediates

the secret enters Vault, gets rotated and disappears from the places it shouldn't have been

The most dangerous secret is the one you don't know you have.

07 · Enterprise and deployment

Ready for the data center

Enterprise capabilities

  • Replication for disaster recovery and performance across data centers
  • Multi-tenant namespaces for separate teams and environments
  • HSM integration and controls for regulated environments
  • Also available on IBM Z and LinuxONE (source: IBM)

Community

open source, to get started and learn the platform

Enterprise self-managed

in your data center or private cloud, with replication, namespaces and HSMs

HCP Vault Dedicated

managed on the HashiCorp Cloud Platform: a dedicated cluster, delegated management

Whichever form you choose, the API and the policies stay the same: you change size, not platform.

08 · Vault and IBM

Vault 2.0: the first major of the IBM era

What's new in release 2.0

  • IBM life cycle: at least 2 years of standard support for every major release
  • Workload Identity Federation towards AWS, Azure and Google Cloud
  • Extended automation of the certificate life cycle in the PKI engine
  • SCIM 2.0 (beta) and SPIFFE workload identity

Sources: HashiCorp and IBM, 2026

IBM Concert

certificate discovery and renewal orchestrated with Vault as the native engine

IBM QRadar SIEM

a dedicated content pack for Vault's security monitoring

Terraform and Ansible

dynamic secrets and rotation inside the provisioning workflows

IBM Z and Power

the safe next to the systems where the data that matters runs

09 · Use cases

Four real problems, a single answer

Databases without fixed passwords

dynamic, time-boxed credentials for every application: the shared, never-rotated account retires

Certificates that renew themselves

An automated PKI and IBM Concert integration: never again services down for an expired certificate

Clean pipelines and repositories

secrets out of the code and CI/CD: Vault Radar hunts them down, Vault guards and rotates them

Encryption for the applications

encryption as a service for sensitive data and GDPR requirements, without managing keys in the apps

From the first use case onwards, Vault becomes a habit: every new service is born already without secrets lying around.

10 · YoctoIT

Var Group's IBM competence center

YoctoIT is a company of the Var Group, services division. We secure secrets and certificates right where the systems we manage every day run: from Power to the cloud.

60+
IBM certifications in the team
200+
active certifications across 16 vendors
H24
NOC active 7 days a week, 365 days a year
99,9%
SLAs met
3.543
hosts monitored by our NOC
100+
active customers, 200+ projects in 3 years

Certified quality: ISO 9001:2015 · ISO 27001:2022 · ISO/IEC 27017 and 27018 · IBM Fusion Certified Partner

“IT that never stops”

11 · How we start

From the assessment to 24/7 management

01

Assessment

Where your secrets live today: code, pipelines, sheets. Immediate quick wins with Vault Radar.

02

Architecture and deployment

Vault in high availability, on-premises or cloud: auth methods, policies and audit configured by the book.

03

App onboarding

Secret engines, rotation, PKI and encryption applied to your real cases, one at a time.

04

24/7 management

Patches, upgrades, audits and monitoring in the YoctoIT Managed Services: the safe never sleeps.

You start small and grow: the first use case in production is worth more than any roadmap.